CVE-2025-36442
IBM Db2 vulnerability analysis and mitigation

Overview

CVE-2025-36442 is a denial-of-service vulnerability in IBM Db2 for Linux, UNIX, and Windows (including Db2 Connect Server) that allows an attacker to crash the database server by sending a specially crafted query involving XML columns. The vulnerability affects versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. It was published on January 30, 2026, with a patch made available shortly after. The CVSS v3.1 base score is 7.5 (High) per NVD, though ENISA rates it 6.5 (Medium) with an authenticated attacker precondition (IBM Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-943 (Improper Neutralization of Special Elements in Data Query Logic), where the Db2 server fails to properly handle special elements within XML column queries. An attacker can exploit this by submitting a specially crafted SQL query targeting XML columns, which triggers an unhandled condition causing the server process to crash. The attack vector is network-based, requires no user interaction, and — depending on the scoring authority — may require low-privilege credentials to execute (IBM Advisory, Red Hat CVE).

Impact

Successful exploitation results in a complete loss of database availability, as the Db2 server process crashes, causing unplanned outages for all applications and users dependent on the affected instance. There is no confidentiality or integrity impact — the vulnerability is limited to availability (DoS). Organizations relying on Db2 for critical workloads face potential service disruption until the server is restarted and the underlying vulnerability is patched (IBM Advisory).

Mitigation and workarounds

IBM has released patches for all affected versions; administrators should upgrade IBM Db2 beyond versions 11.5.9 and 12.1.3 by applying the fixes detailed in IBM's support page. As interim mitigations, organizations should implement network segmentation to restrict database access to trusted hosts only, apply the principle of least privilege to limit which users can execute XML-related queries, and monitor database activity for anomalous query patterns involving XML columns. Applying the vendor patch is the definitive remediation (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10109CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoJun 30, 2026
CVE-2026-9762HIGH7.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoYesJul 17, 2026
CVE-2026-11906MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoJun 30, 2026
CVE-2025-36372MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoYesJun 30, 2026
CVE-2026-7771MEDIUM5.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoYesJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management