CVE-2025-36353: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36353?
CVE-2025-36353 is classified as a denial of service vulnerability which can impact the availability of systems running affected versions of IBM Db2.
How do I fix CVE-2025-36353?
To remediate CVE-2025-36353, upgrade IBM Db2 to a version above 11.5.9 or 12.1.3 as specified by IBM.
What versions of IBM Db2 are affected by CVE-2025-36353?
CVE-2025-36353 affects IBM Db2 for Linux, UNIX and Windows versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3.
Is CVE-2025-36353 a remote exploitation vulnerability?
No, CVE-2025-36353 requires local access to exploit the denial of service condition.
What impact does CVE-2025-36353 have on IBM Db2?
CVE-2025-36353 can lead to a denial of service, making the database unavailable to users.