CVE-2025-36122: IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36122?
CVE-2025-36122 is a denial of service vulnerability that can severely disrupt the availability of IBM Db2 services.
How do I fix CVE-2025-36122?
To mitigate CVE-2025-36122, ensure that the configuration settings for stmtheap are appropriately set and consider upgrading to a patched version of IBM Db2.
Who is affected by CVE-2025-36122?
CVE-2025-36122 affects authenticated users of IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 on Linux, UNIX, and Windows platforms.
Can CVE-2025-36122 be exploited remotely?
CVE-2025-36122 requires an authenticated user to exploit the vulnerability, which typically limits the attack surface.
What versions of IBM Db2 are vulnerable to CVE-2025-36122?
The vulnerable versions of IBM Db2 regarding CVE-2025-36122 are 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3.