CVE-2025-2518
MEDIUMDescription
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
Is your site exposed to CVE-2025-2518?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | db2 |
| ibm | db2 |
| ibm | db2 |
| ibm | db2 |
| ibm | db2 |
| ibm | db2 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-2518? +
How severe is CVE-2025-2518? +
What products are affected by CVE-2025-2518? +
How do I check if I'm vulnerable to CVE-2025-2518? +
Related Vulnerabilities
Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. …
SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length …
Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service …
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through …
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler …
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp …