Privilege Escalation in IBM Db2 for Linux, UNIX and Windows
CVE-2025-36186

7.4HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
7 November 2025

What is CVE-2025-36186?

A privilege escalation vulnerability exists in IBM Db2 versions 12.1.0 to 12.1.3 on Linux, UNIX, and Windows. When configured in certain ways, this flaw allows a local user to execute malicious code, potentially elevating their privileges to root. The issue arises from unnecessary privileges being granted at levels higher than required, creating an opportunity for unauthorized access and control over the system.

Affected Version(s)

Db2 12.1.0 <= 12.1.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36186 : Privilege Escalation in IBM Db2 for Linux, UNIX and Windows