Null Pointer Dereference Vulnerability in Bloomberg Comdb2 Database
CVE-2025-35966
7.5HIGH
What is CVE-2025-35966?
A vulnerability exists in the handling of CDB2SQLQUERY protocol buffer messages in Bloomberg Comdb2 8.1. By sending a specially crafted message to a database instance over TCP, an attacker can induce a denial of service. This issue creates a potential risk for database availability, making it crucial for organizations using this product to assess their systems and apply appropriate mitigations.
Affected Version(s)
Comdb2 8.1