CVE-2025-33012: IBM Db2 improper account lockout
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.
Other sources
IBM Db2 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 V10.5 for Linuxto a version that resolves this vulnerability.Patch DT435638 - Upgrade
Upgrade
IBM Db2 V11.1 for Linuxto a version that resolves this vulnerability.Patch DT435638 - Upgrade
Upgrade
IBM Db2 V11.5 for Linuxto a version that resolves this vulnerability.Patch DT435638 - Upgrade
Upgrade
IBM Db2 V12.1 for Linuxto a version that resolves this vulnerability.Fixed in V12.1.3Patch DT435638
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33012?
CVE-2025-33012 has been rated as having a medium severity level.
How do I fix CVE-2025-33012?
To fix CVE-2025-33012, update your IBM Db2 to the latest version where the vulnerability is addressed.
What versions of IBM Db2 are affected by CVE-2025-33012?
CVE-2025-33012 affects IBM Db2 versions 10.5.0 to 10.5.11, 11.1.0 to 11.1.4.7, 11.5.0 to 11.5.9, and 12.1.0 to 12.1.3.
Can an attacker exploit CVE-2025-33012 remotely?
No, CVE-2025-33012 requires an authenticated user to exploit the vulnerability.
What is the impact of CVE-2025-33012 on user accounts?
CVE-2025-33012 allows an authenticated user to regain access to an account after it has been locked due to password expiration.