Denial of Service Vulnerability in IBM Db2 for Linux, UNIX, and Windows
CVE-2025-36136

5.1MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
7 November 2025

What is CVE-2025-36136?

A vulnerability exists in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 for Linux, UNIX, and Windows. This flaw arises when the database monitor script incorrectly identifies that the database instance is still starting under certain conditions, potentially allowing a local user to trigger a denial of service. This can lead to interruptions in database functionalities, making it critical for businesses relying on these versions to apply the necessary patches and updates.

Affected Version(s)

Db2 11.5.0 <= 11.5.9

Db2 12.1.0 <= 12.1.3

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36136 : Denial of Service Vulnerability in IBM Db2 for Linux, UNIX, and Windows