CVE-2025-36186: IBM Db2 privilege escalation
IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36186?
CVE-2025-36186 has been classified as a high-severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2025-36186?
To mitigate CVE-2025-36186, ensure that all configurations of IBM Db2 are set to only grant necessary permissions and apply the latest security patches from IBM.
Who is affected by CVE-2025-36186?
CVE-2025-36186 affects users of IBM Db2 versions 12.1.0 through 12.1.3 on Linux, UNIX, and Windows platforms.
What type of vulnerability is CVE-2025-36186?
CVE-2025-36186 is classified as a local privilege escalation vulnerability that allows a user to execute malicious code with elevated privileges.
When was CVE-2025-36186 reported?
CVE-2025-36186 was reported as a security vulnerability affecting specific configurations of IBM Db2.