CVE-2025-36001: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36001?
CVE-2025-36001 is classified as a denial of service vulnerability that can affect IBM Db2 versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3.
How can CVE-2025-36001 be exploited?
CVE-2025-36001 can be exploited by an authenticated user who sends a specially crafted SQL statement that triggers uncontrolled recursion, leading to potential service disruption.
What versions of IBM Db2 are affected by CVE-2025-36001?
CVE-2025-36001 affects IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3.
How do I mitigate CVE-2025-36001?
To mitigate CVE-2025-36001, it is recommended to upgrade to a version of IBM Db2 that is not affected by this vulnerability.
Who should be concerned about CVE-2025-36001?
Organizations using IBM Db2 for Linux, UNIX, and Windows versions within the specified ranges should be concerned about CVE-2025-36001 and take appropriate action.