CVE-2025-36247HIGH 8.2EPSS p21.0%

CVE-2025-36247CVE-2025-36247

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Scoring

CVSS 3.18.2 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
EPSS0.30% probability of exploitation · percentile 21.0% · 2026-06-19T12:03:05Z
Published2026-02-17
Last modified2026-02-18

Underlying weaknesses· 1

CWE-611

References

  1. https://www.ibm.com/support/pages/node/7259961

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of XML External Entity Referencecwe-6110%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-12531
CVE
CVE-2025-36049
CVE
CVE-2025-10713
CVE
CVE-2026-3603
CVE
CVE-2026-1718
CVE
CVE-2025-2905
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.