CVE-2025-14688
IBM Db2 vulnerability analysis and mitigation

Overview

CVE-2025-14688 is a denial-of-service vulnerability in IBM Db2 caused by improper neutralization of special elements in data query logic. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 for Linux, UNIX, and Windows, including Db2 Connect Server. The vulnerability was published on April 30, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, IBM Advisory). IBM Application Performance Management products bundling affected Db2 versions are also impacted (IBM APM Advisory).

Technical details

The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input), where the product fails to properly validate quantity-type inputs within data query logic. Exploitation requires an authenticated network-based attacker and is contingent on certain server configurations being present, which raises the attack complexity to High. The vulnerability is triggered when specially crafted query inputs are processed, causing the Db2 engine to enter a denial-of-service condition (GitHub Advisory, IBM Advisory). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an authenticated attacker to cause a denial of service, disrupting availability of the IBM Db2 database service. There is no impact to confidentiality or data integrity — the vulnerability is limited to availability (High impact on availability per CVSS). Affected deployments include standalone Db2 instances as well as Db2 Connect Server and IBM Application Performance Management products that bundle the vulnerable Db2 versions (GitHub Advisory, IBM APM Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2025-14688. The EPSS score is approximately 0.044–0.061%, indicating a low probability of exploitation in the near term (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials and specific server configurations, further limiting the practical attack surface.

Mitigation and workarounds

IBM has released patches addressing this vulnerability; users should apply the fixes referenced in IBM's security advisory for Db2 versions 11.5.x and 12.1.x (IBM Advisory). Organizations using IBM Application Performance Management products that bundle Db2 should also refer to the dedicated APM advisory (IBM APM Advisory). As an interim measure, restricting database access to trusted, authenticated users and reviewing configurations that enable the vulnerable query logic can reduce exposure until patching is complete.

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10534CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-10543CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-16480HIGH7.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-18097MEDIUM5.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-18096LOW3.3
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management