CVE-2025-36098: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper allocation of resources.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36098?
The severity of CVE-2025-36098 is assessed as high due to its potential to cause denial of service.
How do I fix CVE-2025-36098?
To fix CVE-2025-36098, upgrade IBM Db2 to the latest patched version as recommended by IBM support.
Who is affected by CVE-2025-36098?
CVE-2025-36098 affects authenticated users of IBM Db2 for Linux, UNIX, and Windows versions 11.5.x and 12.1.x.
What is the attack vector for CVE-2025-36098?
The attack vector for CVE-2025-36098 involves authenticated users exploiting improper resource allocation to trigger a denial of service.
Is CVE-2025-36098 exploitable remotely?
CVE-2025-36098 is not considered remotely exploitable as it requires authenticated access to the affected systems.