Denial of Service Vulnerability in IBM Db2 for Linux, UNIX, and Windows
CVE-2025-36428
5.3MEDIUM
What is CVE-2025-36428?
An authenticated user can exploit a flaw in IBM Db2 for Linux, UNIX, and Windows, specifically when the RPSCAN feature is activated. The vulnerability arises from improper handling of special elements within data query logic, potentially leading to a denial of service. This issue affects multiple versions of Db2, which organizations must address to secure their database environments effectively.
Affected Version(s)
Db2 for Linux, UNIX and Windows 11.5.0 <= 11.5.9
Db2 for Linux, UNIX and Windows 12.1.0 <= 12.1.3