PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36122 IBM CVE debrief

IBM Db2 vulnerability CVE-2025-36122 allows authenticated users to cause denial of service via specially crafted SQL queries due to improper system resource allocation. This medium-severity vulnerability affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. Db2 administrators and security teams should assess exposure, verify system vulnerability, and prioritize patching or updating affected systems to prevent potential exploitation and denial of service impacts. The vulnerability is caused by improper allocation of system resources when a specially crafted SQL query is used.

Vendor
IBM
Product
Db2
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-30
Original CVE updated
2026-09-30
Advisory published
2026-04-30
Advisory updated
2026-09-30

Who should care

Db2 administrators, security teams, and IT personnel responsible for managing and securing IBM Db2 installations should assess exposure and take necessary actions to mitigate the vulnerability.

Why it matters

CVE-2025-36122 is a medium-severity vulnerability in IBM Db2 that allows authenticated users to cause denial of service via specially crafted SQL queries. Db2 administrators and security teams should assess exposure, verify system vulnerability, and prioritize patching or updating affected systems to prevent potential exploitation and denial of service impacts.

  • Potential denial of service impacting database availability
  • Need for verification of system vulnerability and exposure
  • Priority for applying patches or updates to prevent exploitation
  • Monitoring system resources for unusual patterns indicating potential exploitation attempts

Technical summary

CVE-2025-36122 is a medium-severity vulnerability in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. An authenticated user can cause a denial of service by using a specially crafted SQL query, which leads to improper allocation of system resources. This vulnerability allows authenticated users to cause denial of service via specially crafted SQL queries. Db2 administrators and security teams should assess exposure, verify system vulnerability, and prioritize patching or updating affected systems to prevent potential exploitation and denial of service impacts.

Defensive priority

Medium priority for Db2 administrators and security teams to assess exposure and verify system vulnerability.

Recommended defensive actions

  • Assess exposure of IBM Db2 installations to CVE-2025-36122
  • Verify system vulnerability and apply patches or updates as available
  • Monitor system resources for unusual patterns that could indicate exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and potential impact. Vendor advisory is available from IBM. The vulnerability has been publicly disclosed and its details can be found in the official CVE Program record and the NIST NVD detail page. The affected versions of IBM Db2 are 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. Users should verify their system vulnerability and apply patches or updates as available.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-36122 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-36122

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-36122 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36122

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.