CVE-2025-36184
- EPSS 0.04%
- Veröffentlicht 30.01.2026 21:28:00
- Zuletzt bearbeitet 05.02.2026 20:07:27
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than mini...
CVE-2025-36353
- EPSS 0.01%
- Veröffentlicht 30.01.2026 21:27:57
- Zuletzt bearbeitet 05.02.2026 20:12:28
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
CVE-2025-36365
- EPSS 0.01%
- Veröffentlicht 30.01.2026 21:27:54
- Zuletzt bearbeitet 05.02.2026 19:57:19
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remote storage aliases could allow an authenticated user to execute unauthorized commands due to an author...
CVE-2025-36366
- EPSS 0.02%
- Veröffentlicht 30.01.2026 21:27:51
- Zuletzt bearbeitet 05.02.2026 19:57:27
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that invokes the JSON_Object scalar function, which may trigger an unhandled exception leading to abnormal server t...
CVE-2025-36384
- EPSS 0.01%
- Veröffentlicht 30.01.2026 21:27:48
- Zuletzt bearbeitet 05.02.2026 19:57:35
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.
CVE-2025-36387
- EPSS 0.02%
- Veröffentlicht 30.01.2026 21:27:45
- Zuletzt bearbeitet 05.02.2026 19:57:45
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query.
CVE-2025-36407
- EPSS 0.02%
- Veröffentlicht 30.01.2026 21:27:41
- Zuletzt bearbeitet 09.02.2026 15:16:10
IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
CVE-2025-36423
- EPSS 0.02%
- Veröffentlicht 30.01.2026 21:27:38
- Zuletzt bearbeitet 05.02.2026 19:43:00
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
CVE-2025-36424
- EPSS 0.02%
- Veröffentlicht 30.01.2026 21:27:34
- Zuletzt bearbeitet 11.02.2026 20:57:25
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to improper neutralization of special elements in data query logic.
CVE-2025-36427
- EPSS 0.02%
- Veröffentlicht 30.01.2026 21:27:31
- Zuletzt bearbeitet 11.02.2026 20:57:17
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.