Denial of Service Vulnerability in IBM Db2 for Linux, UNIX, and Windows
CVE-2025-36123

6.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 January 2026

What is CVE-2025-36123?

A vulnerability exists in IBM Db2 for Linux, UNIX, and Windows that may allow a local user to trigger a denial of service condition. This issue arises when the system improperly allocates resources while handling large tables that contain XML data. As a result, a local user could potentially exploit this flaw, leading to service disruptions and system unavailability. For more information, including patches and advisories, please refer to the vendor's support page.

Affected Version(s)

Db2 for Linux, UNIX and Windows 11.5.0 <= 11.5.9

Db2 for Linux, UNIX and Windows 12.1.0 <= 12.1.3

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.