6.5

CVE-2025-1000

IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 

could allow an authenticated user to cause a denial of service when connecting to a z/OS database due to improper handling of automatic client rerouting.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 SwPlatform linux Version >= 11.5 <= 11.5.9
Ibm ≫ Db2 SwPlatform unix Version >= 11.5 <= 11.5.9
Ibm ≫ Db2 SwPlatform windows Version >= 11.5 <= 11.5.9
Ibm ≫ Db2 SwPlatform linux Version >= 12.1.0 <= 12.1.1
Ibm ≫ Db2 SwPlatform unix Version >= 12.1.0 <= 12.1.1
Ibm ≫ Db2 SwPlatform windows Version >= 12.1.0 <= 12.1.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.291
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
IBM 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://www.ibm.com/support/pages/node/7232528
Vendor Advisory
https://security.netapp.com/advisory/ntap-20250516-0002/