CVE-2025-13867: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13867?
CVE-2025-13867 is classified as a denial of service vulnerability affecting specific versions of IBM Db2.
How do I fix CVE-2025-13867?
To mitigate CVE-2025-13867, update your IBM Db2 installation to a patched version that addresses this vulnerability.
Who is affected by CVE-2025-13867?
CVE-2025-13867 affects authenticated users of IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3.
What impact does CVE-2025-13867 have on systems?
Exploitation of CVE-2025-13867 can lead to a denial of service, disrupting the availability of the affected Db2 database services.
Can CVE-2025-13867 be exploited remotely?
CVE-2025-13867 requires authentication, meaning it can only be exploited by users with access to the Db2 database.