Denial of Service Vulnerability in IBM Db2 for Linux, UNIX and Windows
CVE-2025-36424
6.5MEDIUM
What is CVE-2025-36424?
A local user may exploit a vulnerability in IBM Db2 for Linux, UNIX, and Windows, versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3. This vulnerability arises from improper handling of specific elements in data query logic, potentially leading to a denial of service condition. Organizations using the affected Db2 versions should review security best practices and apply the latest vendor patches to mitigate risks.
Affected Version(s)
Db2 for Linux, UNIX and Windows 11.5.0 <= 11.5.9
Db2 for Linux, UNIX and Windows 12.1.0 <= 12.1.3