CVE-2025-36365: IBM Db2 Privilege Escalation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remote storage aliases could allow an authenticated user to execute unauthorized commands due to an authorization bypass vulnerability using a user-controlled key.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configuration of cataloged remote storage aliases could allow an authenticated user to execute unauthorized commands due to an authorization bypass vulnerability using a user-controlled key.
— IBM
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36365?
CVE-2025-36365 is classified as a high-severity vulnerability due to the potential for privilege escalation in IBM Db2.
How do I fix CVE-2025-36365?
To mitigate CVE-2025-36365, update your IBM Db2 installation to the latest version that addresses this vulnerability.
What versions of IBM Db2 are affected by CVE-2025-36365?
CVE-2025-36365 affects IBM Db2 versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3.
Who is impacted by CVE-2025-36365?
Authenticated users of IBM Db2 under specific configurations are at risk due to CVE-2025-36365.
What should I do if I cannot update my IBM Db2 to fix CVE-2025-36365?
If updating is not possible, review your configuration for vulnerabilities and restrict access to sensitive commands as a temporary measure.