---
id: CVE-2023-33854
title: >-
  IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions
  4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass
  client-side validation and manipulate input data using man in the middle
  techniques.
summary: >-
  IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions
  4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass
  client-side validation and manipulate input data using man in the middle
  techniques.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-294
vendor: ibm
product: db2
affected:
  - 'db2 >= 4.8, < 5.4'
  - 'db2_warehouse >= 4.8, < 5.4'
patched:
  - db2 5.4
  - db2_warehouse 5.4
published: '2026-06-22'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T23:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-33854'
references:
  - url: 'https://www.ibm.com/support/pages/node/7277112'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00251
epssPercentile: 0.14733
ingestedAt: '2026-09-26T23:39:28.810Z'
---

## Overview

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.

## Affected

- `db2 >= 4.8, < 5.4`
- `db2_warehouse >= 4.8, < 5.4`

## Remediation

Upgrade past the affected range:

- `db2 5.4`
- `db2_warehouse 5.4`
