Information Exposure Vulnerability in IBM i Database Plan Cache
CVE-2025-36371

6.5MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
19 November 2025

What is CVE-2025-36371?

IBM i versions 7.2 through 7.6 are susceptible to an information exposure vulnerability found in the database plan cache implementation. This flaw allows an authenticated user with access to the database plan cache to view sensitive information that should remain confidential due to authorization restrictions. It is crucial for users of affected versions to apply the security patch provided by IBM to safeguard their data and maintain the integrity of their database environments.

Affected Version(s)

i 7.6

i 7.5

i 7.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36371 : Information Exposure Vulnerability in IBM i Database Plan Cache