PatchSiren cyber security CVE debrief
CVE-2025-36372 IBM CVE debrief
IBM Db2 vulnerability CVE-2025-36372 allows authenticated users to disclose sensitive information from monitoring and event tables. Affected versions include 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 for Linux, UNIX, and Windows. This vulnerability has a medium severity and requires attention from Db2 administrators and security teams to assess exposure and prioritize remediation. The vulnerability affects various platforms, including Linux, UNIX, and Windows, and involves potential sensitive information disclosure to authenticated users. It is essential to verify and update affected Db2 versions and monitor for potential security incidents.
- Vendor
- IBM
- Product
- Db2
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-09-29
Who should care
Db2 administrators, security teams, and IT personnel responsible for monitoring and securing Db2 installations should be aware of this vulnerability. They should assess exposure, prioritize remediation, and monitor for potential security incidents. Affected operators and platforms require attention to prevent potential sensitive information disclosure to authenticated users. Vulnerability management and security team
Why it matters
CVE-2025-36372 is a medium-severity vulnerability in IBM Db2 that allows authenticated users to access sensitive information. Db2 administrators and security teams should assess exposure, prioritize remediation, and monitor for potential security incidents.
- Potential sensitive information disclosure to authenticated users
- Need to verify and update affected Db2 versions
- Monitoring for potential security incidents
Technical summary
CVE-2025-36372 is a vulnerability in IBM Db2 that allows an authenticated user to disclose sensitive information from the monitoring and event tables. The vulnerability affects Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 for Linux, UNIX, and Windows.
Defensive priority
Medium priority for Db2 administrators and security teams
Recommended defensive actions
- Review and apply IBM's vendor advisory
- Check and update affected Db2 versions
- Monitor for potential sensitive information disclosure
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. IBM has released a vendor advisory. The vulnerability has been assessed as medium severity, with potential impacts on sensitive information disclosure. Evidence from the CVE record and NVD entry suggests that affected versions include 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 for Linux, UNIX, and Windows. Defenders should verify affected scope and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-36372 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-36372
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-36372 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36372
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7277417
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.