CVE-2025-3050: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service when using Q replication due to the improper allocation of CPU resources.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service when using Q replication due to the improper allocation of CPU resources.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3050?
CVE-2025-3050 has been classified as a moderate severity vulnerability.
How do I fix CVE-2025-3050?
To fix CVE-2025-3050, ensure that you upgrade IBM Db2 to the latest version beyond 11.5.9 or 12.1.1.
What impact does CVE-2025-3050 have on my system?
CVE-2025-3050 can lead to a denial of service for authenticated users when using Q replication.
Which versions of IBM Db2 are affected by CVE-2025-3050?
CVE-2025-3050 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1.
Is CVE-2025-3050 easy to exploit?
Exploitation of CVE-2025-3050 requires authentication, making it easier for authenticated users but still poses a risk.