CVE-2025-36427: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36427?
The severity of CVE-2025-36427 is classified as moderate, indicating a potential impact on service availability.
How do I fix CVE-2025-36427?
To mitigate CVE-2025-36427, users should upgrade IBM Db2 to a version beyond the affected ranges of 11.5.9 or 12.1.3.
What versions of IBM Db2 are affected by CVE-2025-36427?
CVE-2025-36427 affects IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3.
What type of vulnerability is CVE-2025-36427?
CVE-2025-36427 is a denial of service vulnerability caused by improper neutralization of special elements in data query logic.
Can CVE-2025-36427 be exploited by remote users?
No, CVE-2025-36427 requires local access for exploitation, making it less likely to be targeted by remote attackers.