PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36372 IBM CVE debrief

IBM Db2 vulnerability CVE-2025-36372 allows authenticated users to disclose sensitive information from monitoring and event tables. Affected versions include 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 for Linux, UNIX, and Windows. This vulnerability has a medium severity and requires attention from Db2 administrators and security teams to assess exposure and prioritize remediation. The vulnerability affects various platforms, including Linux, UNIX, and Windows, and involves potential sensitive information disclosure to authenticated users. It is essential to verify and update affected Db2 versions and monitor for potential security incidents.

Vendor
IBM
Product
Db2
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-09-29
Advisory published
2026-06-30
Advisory updated
2026-09-29

Who should care

Db2 administrators, security teams, and IT personnel responsible for monitoring and securing Db2 installations should be aware of this vulnerability. They should assess exposure, prioritize remediation, and monitor for potential security incidents. Affected operators and platforms require attention to prevent potential sensitive information disclosure to authenticated users. Vulnerability management and security team

Why it matters

CVE-2025-36372 is a medium-severity vulnerability in IBM Db2 that allows authenticated users to access sensitive information. Db2 administrators and security teams should assess exposure, prioritize remediation, and monitor for potential security incidents.

  • Potential sensitive information disclosure to authenticated users
  • Need to verify and update affected Db2 versions
  • Monitoring for potential security incidents

Technical summary

CVE-2025-36372 is a vulnerability in IBM Db2 that allows an authenticated user to disclose sensitive information from the monitoring and event tables. The vulnerability affects Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 for Linux, UNIX, and Windows.

Defensive priority

Medium priority for Db2 administrators and security teams

Recommended defensive actions

  • Review and apply IBM's vendor advisory
  • Check and update affected Db2 versions
  • Monitor for potential sensitive information disclosure

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. IBM has released a vendor advisory. The vulnerability has been assessed as medium severity, with potential impacts on sensitive information disclosure. Evidence from the CVE record and NVD entry suggests that affected versions include 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 for Linux, UNIX, and Windows. Defenders should verify affected scope and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-36372 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-36372

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-36372 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36372

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.