CVE-2025-36372
MEDIUM
5.5
CVSS 3.1
Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.
Metadata
Severity & Metrics
5.5
MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| IBM | Db2 | — | 11.5.0 ≤ 11.5.9, 12.1.0 ≤ 12.1.4 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-538 | cna | CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.5 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
References (1)