CVE-2025-36425: IBM Db2 Information Disclosure
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to obtain sensitive information under specific HADR configuration.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36425?
CVE-2025-36425 is classified as a medium severity vulnerability due to potential information disclosure.
How do I fix CVE-2025-36425?
To fix CVE-2025-36425, upgrade IBM Db2 to version 11.5.10 or 12.1.4 or later.
Who is affected by CVE-2025-36425?
CVE-2025-36425 affects IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3.
What type of vulnerability is CVE-2025-36425?
CVE-2025-36425 is an information disclosure vulnerability that allows authenticated users to access sensitive information.
What conditions must be met for CVE-2025-36425 to be exploited?
CVE-2025-36425 can be exploited under specific HADR configuration settings.