Because this JDK is bundled with IBM Data Server Client, don’t replace the files under SQLLIB with a standalone Oracle JDK, OpenJDK, or Semeru installation.
IBM’s supported remediation path is to first match the reported CVEs against the published Db2 security vulnerabilities. The applicable bulletin will identify the required Db2 fix pack, special build, or IBM JDK update. IBM’s Db2 security bulletins state that affected Db2 11.5 installations can use the appropriate special build or download the applicable IBM JDK update from Fix Central and follow IBM’s installation instructions.
Before changing anything:
- Record the complete IBM Data Server Client 11.5 fix-pack level, not only the major version.
- Identify the exact CVEs Cyberport reported.
- Locate the corresponding IBM Db2 security bulletin and apply only the remediation specified for that Db2 level and Windows architecture.
- Back up the current installation and test the update with the dependent applications before production deployment.
IBM Db2/SQLLIB Support should confirm the correct package and compatibility path because the runtime belongs to the Db2 client installation. Your infrastructure team can perform the Windows change, while the application owners should validate the dependent applications afterward. This ownership split is an operational recommendation.
I cannot recommend a specific JDK build replacement without the exact CVE list and the complete Db2 fix pack level.
References:
IBM: Published security vulnerabilities for Db2 for Linux, UNIX and Windows
IBM: Instructions for IBM JDK installation for a security-related fix
IBM: Multiple IBM Semeru vulnerabilities affecting Db2 - April 2026 CPU
IBM: Fix list for Db2 Version 11.5 for Linux, UNIX and Windows
IBM: Db2 11.5 system requirements
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.