CVE-2025-2669: Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.
Other sources
IBM Db2U could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 - Upgrade
Upgrade
IBM Db2 Warehouse on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 - Upgrade
Upgrade
IBM Db2Uto a version that resolves this vulnerability.Fixed in 5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2669?
The severity of CVE-2025-2669 is classified as medium with a score of 6.
How can I mitigate CVE-2025-2669?
Mitigation for CVE-2025-2669 involves correcting the improper token validation to prevent unauthorized operations.
Which versions of IBM Db2 on Cloud Pak for Data are affected by CVE-2025-2669?
CVE-2025-2669 affects versions 4.8, 5.0, 5.1, 5.2, and 5.3 of IBM Db2 on Cloud Pak for Data.
What type of exposure does CVE-2025-2669 allow?
CVE-2025-2669 allows a privileged user to perform operations and access sensitive information outside of their authorized privileges.
What is the potential impact of CVE-2025-2669?
The potential impact of CVE-2025-2669 includes unauthorized information disclosure and access to sensitive data.