MEDIUM🇵🇱 Wersja polska

CVE-2025-33012

CVSS 6.3v3.1pub. 2025-11-07upd. 2025-11-19

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
  • IBM Db2

    APP
    Ibm
    10.5.0.0 – 10.5.0.1111.1.0 – 11.1.4.711.5.0 – 11.5.912.1.0 – 12.1.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-10109CRITICAL9.8PL ✓same product

RCE w IBM Db2 — błąd obsługi pre-auth DRDA handshake

CVE-2026-10543HIGH8.2same product

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a speciall...

CVE-2026-10534HIGH8.4same product

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT pa...

CVE-2026-10535HIGH8.4PL ✓same product

Buffer overflow w IBM Db2 — podatność w helperie db2flacc (setgid)

CVE-2026-9762HIGH7.8PL ✓same product

IBM Db2 — RCE poprzez kontrolowany przez użytkownika JDBC URL