Denial of Service Vulnerability in IBM Db2 Database on Multiple Platforms
CVE-2025-14688

5.3MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2025-14688?

An issue in IBM Db2 versions 11.5 (0-9) and 12.1 (0-3) for Linux, UNIX, and Windows systems has been identified, where improper handling of certain elements in data query logic by an authenticated user can lead to a denial of service. This vulnerability may occur under specific configurations, potentially disrupting service availability for the affected database systems.

Affected Version(s)

Db2 11.5.0 <= 11.5.9

Db2 12.1.0 <= 12.1.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.