CVE-2025-14688: IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14688?
CVE-2025-14688 is classified as a denial of service vulnerability affecting specific versions of IBM Db2.
How do I fix CVE-2025-14688?
To mitigate CVE-2025-14688, upgrade your IBM Db2 to the latest version that includes security fixes.
Which products are affected by CVE-2025-14688?
CVE-2025-14688 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3.
Who is at risk from CVE-2025-14688?
Authenticated users of vulnerable versions of IBM Db2 are at risk from CVE-2025-14688.
What impact does CVE-2025-14688 have?
CVE-2025-14688 can cause a denial of service by fetching from specific tables under certain configurations.