CVE-2025-36001
IBM Db2 vulnerability analysis and mitigation

Overview

CVE-2025-36001 is an uncontrolled recursion vulnerability in IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) that allows an authenticated user to cause a denial of service via a specially crafted SQL statement containing XML. Affected versions include 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 across all supported platforms. The vulnerability was published on January 30, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 6.5 (Medium) (IBM Support, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-674 (Uncontrolled Recursion) and resides in IBM Db2's XML processing subsystem. An authenticated attacker can submit a specially crafted SQL statement that includes XML content designed to trigger deeply nested or infinite recursion within the database engine. The attack vector is network-based, requires low privileges (valid database credentials), and no user interaction, making it straightforward to exploit once access is obtained. No complex preconditions beyond authentication are required (IBM Support, Red Hat CVE).

Impact

Successful exploitation results in a high availability impact — the affected Db2 instance can become unresponsive, crash, or consume excessive system resources, disrupting database service for all dependent applications and users. There is no confidentiality or integrity impact, as the vulnerability is limited to a denial-of-service condition. The scope is unchanged, meaning the impact is confined to the affected Db2 instance itself without lateral spread to other systems (IBM Support).

Exploitation steps

  1. Reconnaissance: Identify IBM Db2 instances running versions 11.5.0–11.5.9 or 12.1.0–12.1.3 on Linux, UNIX, or Windows that are network-accessible.
  2. Authentication: Obtain valid database credentials (low-privilege user account is sufficient) through credential theft, phishing, or brute force.
  3. Craft malicious SQL: Construct a SQL statement that incorporates XML content designed to trigger deeply nested or infinite recursive processing within Db2's XML engine (e.g., using recursive XML structures or self-referencing XML entities).
  4. Execute the payload: Submit the crafted SQL statement to the target Db2 instance via a database client, JDBC/ODBC connection, or any application interface that passes SQL to the database.
  5. Achieve denial of service: The uncontrolled recursion causes the Db2 process to consume excessive CPU/memory resources or crash, rendering the database unavailable to legitimate users (IBM Support).

Indicators of compromise

  • Logs: Database audit logs showing repeated or unusual SQL statements containing deeply nested XML structures or recursive XML patterns submitted by a single user account.
  • Process: Db2 engine processes exhibiting abnormally high CPU or memory consumption without corresponding legitimate workload.
  • Availability: Sudden unresponsiveness or crashes of the Db2 service, particularly following execution of XML-containing SQL queries.
  • Network: Unusual or repeated database connections from unexpected source IPs submitting XML-heavy SQL workloads.

Mitigation and workarounds

IBM has released security patches for all affected versions; administrators should apply the updates referenced in IBM Support page node/7257616 for their specific version (11.5.0–11.5.9 or 12.1.0–12.1.3). As interim mitigations, restrict database access to only authenticated users who require it and enforce the principle of least privilege for database accounts. Additionally, monitor for and consider filtering SQL statements containing deeply nested or recursive XML structures, and review database audit logs for suspicious XML-based query patterns (IBM Support).

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10109CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoJun 30, 2026
CVE-2026-9762HIGH7.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoYesJul 17, 2026
CVE-2026-11906MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoJun 30, 2026
CVE-2025-36372MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoYesJun 30, 2026
CVE-2026-7771MEDIUM5.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoYesJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management