Denial of Service Vulnerability in IBM Db2 for Linux, UNIX, and Windows
CVE-2025-36006

6.5MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
7 November 2025

What is CVE-2025-36006?

A vulnerability in IBM Db2 could allow authenticated users to cause a denial of service due to improper resource management. This affects various versions of IBM Db2 across platforms, where inadequate handling of resources may result in system disruptions. To mitigate the risks associated with this vulnerability, it is recommended that users promptly apply patches available through IBM support.

Affected Version(s)

Db2 10.5.0 <= 10.5.11

Db2 11.1.0 <= 11.1.4.7

Db2 11.5.0 <= 11.5.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36006 : Denial of Service Vulnerability in IBM Db2 for Linux, UNIX, and Windows