Cyber Posture

CVE-2025-36442

Medium

Published: 30 January 2026

Published
30 January 2026
Modified
05 February 2026
KEV Added
Patch
CVSS Score 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0002 6.5th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-36442 is a medium-severity Improper Neutralization of Special Elements in Data Query Logic (CWE-943) vulnerability in Ibm Db2. Its CVSS base score is 6.5 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked at the 6.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense at a Glance

What attackers do: exploitation maps to Application or System Exploitation (T1499.004).
Threat & Defense Details

MITRE ATT&CK Enterprise TechniquesAI

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

Direct mapping to application/system exploitation causing crash/DoS via crafted remote query input.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML…

more

columns.

Deeper analysisAI

CVE-2025-36442 is a denial-of-service vulnerability affecting IBM Db2 for Linux, UNIX, and Windows, including Db2 Connect Server, in versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. The issue arises when the server processes a specially crafted query involving XML columns under certain conditions, potentially causing a crash. It carries a CVSS v3.1 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) and is linked to CWE-943 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ("Injection")) with additional NVD-CWE-noinfo classification. The vulnerability was published on 2026-01-30.

An attacker requires low privileges (PR:L) and can exploit this remotely over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N). By submitting the crafted query, the attacker can crash the Db2 server, achieving high-impact denial of service (A:H) through availability disruption, with no effects on confidentiality or integrity and no change in scope (S:U).

IBM's security advisory at https://www.ibm.com/support/pages/node/7257698 provides details on the vulnerability, affected versions, and recommended mitigations, including available patches.

Details

CWE(s)

Affected Products

ibm
db2
11.5.0 — 11.5.9 · 11.5.0 — 11.5.9 · 11.5.0 — 11.5.9

CVEs Like This One

CVE-2025-36070Same product: Ibm Db2
CVE-2025-36247Same product: Ibm Db2
CVE-2025-36384Same product: Ibm Db2
CVE-2025-36365Same product: Ibm Db2
CVE-2025-36184Same product: Ibm Db2
CVE-2025-1403Same vendor: Ibm
CVE-2025-3356Same vendor: Ibm
CVE-2025-36094Same vendor: Ibm
CVE-2026-1376Same vendor: Ibm
CVE-2025-12531Same vendor: Ibm

References