IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
History

Wed, 18 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*

Tue, 17 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 17:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Title IBM Db2 XML External Entity Reference
First Time appeared Ibm
Ibm db2
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:zos:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:zos:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:zos:*:*
cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:zos:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-02-17T17:13:06.775Z

Updated: 2026-02-17T19:21:41.367Z

Reserved: 2025-04-15T21:16:43.936Z

Link: CVE-2025-36247

cve-icon Vulnrichment

Updated: 2026-02-17T19:11:49.556Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-17T18:20:29.940

Modified: 2026-02-18T19:23:13.760

Link: CVE-2025-36247

cve-icon Redhat

No data.