6.5
CVE-2025-33130
- EPSS 0.06%
- Veröffentlicht 17.02.2026 19:14:48
- Zuletzt bearbeitet 20.02.2026 21:01:45
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windows
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Merge Backup Version12.1.0.0 SwPlatformlinux
Ibm ≫ Db2 Merge Backup Version12.1.0.0 SwPlatformunix
Ibm ≫ Db2 Merge Backup Version12.1.0.0 SwPlatformwindows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.192 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.