CVE-2025-1493Race Condition in IBM DB2

CWE-362Race Condition3 documents3 sources
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 50.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 5

Description

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service due to concurrent execution of shared resources.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages1 packages

NVDibm/db212.1.012.1.1

🔴Vulnerability Details

2
GHSA
GHSA-8863-jfm6-35xm: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 122025-05-05
CVEList
IBM Db2 denial of service2025-05-05
CVE-2025-1493 — Race Condition in IBM DB2 | cvebase