
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36442 is a denial-of-service vulnerability in IBM Db2 for Linux, UNIX, and Windows (including Db2 Connect Server) that allows an attacker to crash the database server by sending a specially crafted query involving XML columns. The vulnerability affects versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. It was published on January 30, 2026, with a patch made available shortly after. The CVSS v3.1 base score is 7.5 (High) per NVD, though ENISA rates it 6.5 (Medium) with an authenticated attacker precondition (IBM Advisory, Red Hat CVE).
The root cause is classified as CWE-943 (Improper Neutralization of Special Elements in Data Query Logic), where the Db2 server fails to properly handle special elements within XML column queries. An attacker can exploit this by submitting a specially crafted SQL query targeting XML columns, which triggers an unhandled condition causing the server process to crash. The attack vector is network-based, requires no user interaction, and — depending on the scoring authority — may require low-privilege credentials to execute (IBM Advisory, Red Hat CVE).
Successful exploitation results in a complete loss of database availability, as the Db2 server process crashes, causing unplanned outages for all applications and users dependent on the affected instance. There is no confidentiality or integrity impact — the vulnerability is limited to availability (DoS). Organizations relying on Db2 for critical workloads face potential service disruption until the server is restarted and the underlying vulnerability is patched (IBM Advisory).
IBM has released patches for all affected versions; administrators should upgrade IBM Db2 beyond versions 11.5.9 and 12.1.3 by applying the fixes detailed in IBM's support page. As interim mitigations, organizations should implement network segmentation to restrict database access to trusted hosts only, apply the principle of least privilege to limit which users can execute XML-related queries, and monitor database activity for anomalous query patterns involving XML columns. Applying the vendor patch is the definitive remediation (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."