
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14688 is a denial-of-service vulnerability in IBM Db2 caused by improper neutralization of special elements in data query logic. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 for Linux, UNIX, and Windows, including Db2 Connect Server. The vulnerability was published on April 30, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, IBM Advisory). IBM Application Performance Management products bundling affected Db2 versions are also impacted (IBM APM Advisory).
The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input), where the product fails to properly validate quantity-type inputs within data query logic. Exploitation requires an authenticated network-based attacker and is contingent on certain server configurations being present, which raises the attack complexity to High. The vulnerability is triggered when specially crafted query inputs are processed, causing the Db2 engine to enter a denial-of-service condition (GitHub Advisory, IBM Advisory). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an authenticated attacker to cause a denial of service, disrupting availability of the IBM Db2 database service. There is no impact to confidentiality or data integrity — the vulnerability is limited to availability (High impact on availability per CVSS). Affected deployments include standalone Db2 instances as well as Db2 Connect Server and IBM Application Performance Management products that bundle the vulnerable Db2 versions (GitHub Advisory, IBM APM Advisory).
No public exploit code or in-the-wild exploitation has been reported for CVE-2025-14688. The EPSS score is approximately 0.044–0.061%, indicating a low probability of exploitation in the near term (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials and specific server configurations, further limiting the practical attack surface.
IBM has released patches addressing this vulnerability; users should apply the fixes referenced in IBM's security advisory for Db2 versions 11.5.x and 12.1.x (IBM Advisory). Organizations using IBM Application Performance Management products that bundle Db2 should also refer to the dedicated APM advisory (IBM APM Advisory). As an interim measure, restricting database access to trusted, authenticated users and reviewing configurations that enable the vulnerable query logic can reduce exposure until patching is complete.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."