CVE-2025-36353 | IBM DB2/DB2 Connect Server up to 11.5.9/12.1.3 Data Query Logic data query logic injection (EUVD-2025-206557)
A vulnerability marked as problematic has been reported in IBM DB2 and DB2 Connect Server up to 11.5.9/12.1.3. This affects an unknown part of the component Data Query Logic. This manipulation causes improper neutralization of special elements in data query logic.
This vulnerability appears as CVE-2025-36353. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.