02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: ibmIBM Db2 for Linux denial of service
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
- SSVC decision
- ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
- AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
- Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 0.31% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 22.7% of scored records. A rank, not a probability.
- NVD base score
- 7.5 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- NVD analysis status
- Analyzed. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2025-07-29 18:41Z1 YR AGO
- Last updated
- 2025-07-29 18:47Z1 YR AGO
- Reserved
- 2025-04-15
- Assigning CNA
- ibm
- Record state
- PUBLISHED
- Severity
- Medium (CVSS 5.3)
- CNA CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- Weaknesses
- CWE-943Improper Neutralization of Special Elements in Data Query LogicClass
- Data version
- 5.1
- Document digest
- f3443e7716a120ad134b4b2a79613d32caaf036c7cda793634bdab6366f73627
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
IBMDb212.1.0, 12.1.1, 12.1.2Linux SRC: CNA
Customers running any vulnerable affected level of an affected Program, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent affected level for each impacted release: V12.1.1, V12.1.2. They can be applied to any affected mod pack level of the appropriate release to remediate this vulnerability.
Release Fixed in mod pack APAR Download URL
V12.1 V12.1.2 DT426060
Special Build #62100 or later for V12.1.1 available at this link:
https://www.ibm.com/support/pages/db2-v1211-published-cumulative-special-build-downloads#52441
12.1.2 Latest:
https://www.ibm.com/support/pages/db2-v1212-published-cumulative-special-build-downloads
IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.
Note: After December 31, 2025, 11.1 and 10.5 versions of Db2 will not have security fixes made available as they will reach EoS.