CVE-2025-36384: IBM DB2
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.
Affected products
- IBM DB2: from 12.1.0, up to and including 12.1.3
Published 2026-01-30. Last modified 2026-06-17.