CVE-2025-36186

7.4

IBM · Db2

IBM Db2 12.1.0 through 12.1.3 contains a privilege escalation vulnerability due to the execution of unnecessary privileges.

Executive summary

IBM Db2 versions 12.1.0 through 12.1.3 are vulnerable to a local privilege escalation flaw that could allow a user to gain root access.

Vulnerability

This vulnerability is classified as CWE-250, Execution with Unnecessary Privileges, where improper configuration allows a local user to escalate their system privileges to root. The vulnerability requires local access to the system, though it does not explicitly require prior authentication to the database application itself to exploit the underlying flaw.

Business impact

The potential for root-level privilege escalation poses a severe risk to the confidentiality, integrity, and availability of the host server. An attacker who successfully exploits this flaw can bypass system security controls, access sensitive database information, or modify critical system configurations, leading to a complete compromise of the affected host. With a CVSS score of 7.4, this vulnerability is considered a high-severity risk that demands immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Apply the vendor-provided special build containing the interim fix for this issue, specifically targeting release V12.1.3 with APAR DT445866 or later, as documented on IBM Fix Central.

Proactive Monitoring: Audit local system logs for unauthorized attempts to escalate privileges or unexpected execution of administrative commands by standard user accounts.

Compensating Controls: Implement the principle of least privilege by restricting local login access to the database server to only essential personnel and hardening the operating system environment to limit attack surfaces.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for full system compromise via root privilege escalation, it is imperative that organizations running IBM Db2 12.1.0 through 12.1.3 prioritize the deployment of the provided special build. Administrators should verify their current versioning and apply the necessary patches through IBM Fix Central to eliminate the risk of privilege escalation. Monitoring for suspicious local activity remains a critical secondary measure until all affected systems are fully remediated.

More IBM CVEs

Sources