CVE-2025-36184: IBM Db2 Privilege Escalation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36184?
The severity of CVE-2025-36184 is high due to its potential for privilege escalation in IBM Db2.
How do I fix CVE-2025-36184?
To fix CVE-2025-36184, upgrade IBM Db2 to version 11.5.10 or later where the vulnerability is addressed.
What systems are affected by CVE-2025-36184?
CVE-2025-36184 affects IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 to 11.5.9.
What is the impact of CVE-2025-36184 on IBM Db2?
CVE-2025-36184 allows an instance owner to execute malicious code that could escalate their privileges to root.
Who is at risk from CVE-2025-36184?
Organizations using affected versions of IBM Db2 are at risk from CVE-2025-36184 due to the privilege escalation vulnerability.