CVE-2025-2668: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when an authenticated user creates a specially crafted query.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an authenticated user creates a specially crafted query.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2668?
CVE-2025-2668 is rated as a high severity vulnerability due to its potential to cause a denial of service.
How does CVE-2025-2668 exploit IBM Db2?
CVE-2025-2668 exploits IBM Db2 by crashing the server through a specially crafted query from an authenticated user.
Which versions of IBM Db2 are affected by CVE-2025-2668?
CVE-2025-2668 affects IBM Db2 versions 11.5.0 to 11.5.9.
What are the consequences of not fixing CVE-2025-2668?
Not fixing CVE-2025-2668 can lead to service interruptions and potential downtime for applications reliant on IBM Db2.
How can I mitigate CVE-2025-2668?
To mitigate CVE-2025-2668, it is recommended to update IBM Db2 to a version that addresses this denial of service vulnerability.