CVE-2025-36428: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.
— IBM
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36428?
CVE-2025-36428 is classified as a denial of service vulnerability that affects specific versions of IBM Db2.
How do I fix CVE-2025-36428?
To mitigate CVE-2025-36428, disable the RPSCAN feature in IBM Db2 if it is currently enabled.
Who is affected by CVE-2025-36428?
CVE-2025-36428 affects authenticated users of IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3.
What causes CVE-2025-36428?
CVE-2025-36428 is caused by improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.
Can CVE-2025-36428 be exploited remotely?
CVE-2025-36428 requires authentication, meaning it cannot be exploited remotely by unauthenticated users.