VYPR
Medium severity5.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026

CVE-2025-36372

CVE-2025-36372

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.

Affected products

2
  • IBM/Db22 versions
    cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*range: >=11.5.0,<11.5.9
    • (no CPE)range: 11.5.0-11.5.9, 12.1.0-12.1.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.