Privilege Escalation in IBM Db2 for Linux, UNIX and Windows
CVE-2025-36186
7.4HIGH
What is CVE-2025-36186?
A privilege escalation vulnerability exists in IBM Db2 versions 12.1.0 to 12.1.3 on Linux, UNIX, and Windows. When configured in certain ways, this flaw allows a local user to execute malicious code, potentially elevating their privileges to root. The issue arises from unnecessary privileges being granted at levels higher than required, creating an opportunity for unauthorized access and control over the system.
Affected Version(s)
Db2 12.1.0 <= 12.1.3
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved