
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM Db2 for Linux versions 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service attack that can be triggered with a specially crafted query under certain non-default conditions. The vulnerability was disclosed on July 29, 2025, and has been assigned CVE-2025-33114 (IBM Advisory, NVD).
The vulnerability is classified as CWE-943: Improper Neutralization of Special Elements in Data Query Logic. It has received varying CVSS severity scores, with the NVD assigning a base score of 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, while IBM Corporation assigned a base score of 5.3 (MEDIUM) with vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H (IBM Advisory, NVD).
The vulnerability affects the availability of IBM Db2 systems, potentially allowing attackers to cause a denial of service condition. The impact is limited to Linux and Unix systems, while Windows installations are not affected (IBM Advisory).
IBM has released special builds containing interim fixes for the affected versions. For version 12.1.1, Special Build #62100 or later is available, and for version 12.1.2, a latest special build has been released. These can be applied to any affected mod pack level of the appropriate release. No workarounds are available for this vulnerability (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."