CVE-2025-36372
IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.
INFO
Published Date :
June 30, 2026, 8:03 p.m.
Last Modified :
June 30, 2026, 8:03 p.m.
Remotely Exploit :
No
Source :
ibm
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | 9a959283-ebb5-44b6-b705-dcc2bbced522 |
Solution
- Update IBM Db2 to the latest available version.
- Consult IBM documentation for specific security fixes.
- Review access controls for monitoring tables.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-36372 vulnerability anywhere in the article.