CVE-2025-36247 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity inject…
High CVSS: 7.1

CVE-2025-36247

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Vendor
Ibm
Product
Db2
CWE
CWE-611
Yayın Tarihi
2026-02-17 18:20:29
Güncelleme
2026-02-18 19:23:13
Source Identifier
psirt@us.ibm.com
KEV Date Added
-

Kategoriler

Referanslar