CVE-2025-36247: IBM Db2 XML External Entity Reference
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36247?
The severity of CVE-2025-36247 is high with a CVSS score of 8.2.
What software is affected by CVE-2025-36247?
CVE-2025-36247 affects IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3.
How do I fix CVE-2025-36247?
To fix CVE-2025-36247, download the special build containing the interim fix from Fix Central for the affected versions.
What type of attack is associated with CVE-2025-36247?
CVE-2025-36247 is associated with XML external entity (XXE) injection attacks.
What could a remote attacker achieve by exploiting CVE-2025-36247?
A remote attacker exploiting CVE-2025-36247 could expose sensitive information or consume system resources.