Cyber Posture

CVE-2025-13108

Medium

Published: 17 February 2026

Published
17 February 2026
Modified
26 February 2026
KEV Added
Patch
CVSS Score 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0003 10.3th percentile
Risk Priority 11 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-13108 is a medium-severity Sensitive Information in Resource Not Removed Before Reuse (CWE-226) vulnerability in Ibm Db2 Merge Backup. Its CVSS base score is 5.5 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Local System (T1005); ranked at the 10.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense at a Glance

What attackers do: exploitation maps to Data from Local System (T1005).
Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-226

The eradication and cross-system identification steps ensure sensitive information is removed before resources are reused or further accessed.

addresses: CWE-226

Requiring sanitization of media prior to removal for off-site maintenance ensures sensitive information is removed before the resource is reused or accessed externally.

addresses: CWE-226

Procedures include sanitization, overwriting, and disposal requirements to remove sensitive data before media reuse or release.

addresses: CWE-226

Requiring sanitization prior to reuse directly ensures sensitive information is removed from resources before they are reused by others.

addresses: CWE-226

Downgrading enables reuse of media at lower security levels, and the mandated process ensures sensitive information is removed beforehand to prevent exposure on reused resources.

addresses: CWE-226

Directly requires removal of sensitive data from resources before reuse or reallocation to another subject, eliminating residual information transfer.

addresses: CWE-226

Explicit retention limits and destruction rules reduce the persistence of sensitive information in reusable resources.

addresses: CWE-226

Periodic quality checks and deletion ensure sensitive PII is removed from resources prior to reuse or retention beyond its valid lifetime.

MITRE ATT&CK Enterprise TechniquesAI

T1005 Data from Local System Collection
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Why these techniques?

Vulnerability enables local reading of residual sensitive data (e.g., credentials) from uncleared memory buffers.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v18.1

NVD Description

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

Deeper analysisAI

CVE-2025-13108 affects IBM DB2 Merge Backup for Linux, UNIX, and Windows version 12.1.0.0. The vulnerability arises because a buffer does not properly clear resources, potentially allowing an attacker to access sensitive information stored in memory. It is classified under CWE-226 (Sensitive Information in Resource Not Removed Before Reuse) and has a CVSS v3.1 base score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), indicating medium severity with high confidentiality impact but no integrity or availability effects.

A local attacker with low privileges can exploit this issue with low complexity and no user interaction required. Successful exploitation enables the reading of sensitive data from memory that should have been cleared, potentially exposing confidential information such as credentials, keys, or other runtime data without altering system integrity or availability.

IBM's security advisory at https://www.ibm.com/support/pages/node/7260043 provides details on mitigation, including available patches for the affected DB2 Merge Backup component. Security practitioners should review the advisory for fix packs and apply them promptly to remediate the buffer clearing deficiency.

Details

CWE(s)

Affected Products

ibm
db2 merge backup
12.1.0.0

CVEs Like This One

CVE-2026-0977Same vendor: Ibm
CVE-2025-1722Same vendor: Ibm
CVE-2024-56340Same vendor: Ibm
CVE-2025-0162Same vendor: Ibm
CVE-2026-1567Same vendor: Ibm
CVE-2026-4788Same vendor: Ibm
CVE-2025-13096Same vendor: Ibm
CVE-2024-41771Same vendor: Ibm
CVE-2024-31896Same vendor: Ibm
CVE-2025-14923Same vendor: Ibm

References