First published: Mon May 05 2025(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service due to concurrent execution of shared resources.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | <=12.1.0 - 12.1.1 |
Customers running any vulnerable fixpack level of an affected Program, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent fixpack level for each impacted release: V12.1. They can be applied to any affected fixpack level of the appropriate release to remediate this vulnerability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1493 is classified as a denial of service vulnerability affecting IBM Db2 versions 12.1.0 through 12.1.1.
To mitigate CVE-2025-1493, apply the latest security patches provided by IBM for Db2 versions 12.1.0 and 12.1.1.
CVE-2025-1493 affects authenticated users of IBM Db2 for Linux, UNIX, and Windows versions 12.1.0 and 12.1.1.
The impact of CVE-2025-1493 is a potential denial of service due to concurrent execution of shared resources.
CVE-2025-1493 is not considered remote; it requires authentication to exploit the vulnerability.