{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-36387","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-04-15T21:16:57.302Z","datePublished":"2026-01-30T21:27:45.304Z","dateUpdated":"2026-02-02T16:31:10.387Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:linux:*:*","cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:unix:*:*","cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:aix:*:*","cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:windows:*:*","cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:zos:*:*","cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:linux:*:*","cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:unix:*:*","cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:aix:*:*","cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:windows:*:*","cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:zos:*:*","cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:linux:*:*","cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:unix:*:*","cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:aix:*:*","cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:windows:*:*","cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:zos:*:*","cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:linux:*:*","cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:unix:*:*","cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:aix:*:*","cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:windows:*:*","cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:zos:*:*"],"defaultStatus":"unaffected","product":"Db2 for Linux, UNIX and Windows","vendor":"IBM","versions":[{"lessThanOrEqual":"11.5.9","status":"affected","version":"11.5.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query.</p><br>"}],"value":"IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-770","description":"CWE-770 Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-01-30T21:38:33.190Z"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7257690"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><p>Customers running any vulnerable modpack level of an affected Program, V11.5 , can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9. They can be applied to any affected level of the appropriate release to remediate this vulnerability.</p><p>&nbsp;</p><div><table><tbody><tr><td><strong>Release</strong></td><td><strong>Fixed in mod pack</strong></td><td><strong>APAR</strong></td><td><strong>Download URL</strong></td></tr><tr><td>V11.5</td><td>TBD</td><td><a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ00000057Yj/dt450298\">DT450298</a></td><td><p>Special Build #66394 or later for V11.5.9 available at this link:<br><a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/node/7087189\">https://www.ibm.com/support/pages/node/7087189</a></p></td></tr></tbody></table></div><p>&nbsp;</p><p>IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.</p></div><div><br></div><br>"}],"value":"Customers running any vulnerable modpack level of an affected Program, V11.5 , can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n \n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\n \n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."}],"source":{"discovery":"UNKNOWN"},"title":"IBM Db2 Denial of Service","x_generator":{"engine":"Vulnogram 0.5.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-02-02T16:25:29.737152Z","id":"CVE-2025-36387","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-02T16:31:10.387Z"}}]}}