CVE-2025-36366 | IBM DB2/DB2 Connect Server up to 11.5.9/12.1.3 Data Query Logic data query logic injection (EUVD-2025-206559)
A vulnerability described as problematic has been identified in IBM DB2 and DB2 Connect Server up to 11.5.9/12.1.3. This vulnerability affects unknown code of the component Data Query Logic. Such manipulation leads to improper neutralization of special elements in data query logic.
This vulnerability is traded as CVE-2025-36366. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.