CVE-2025-36442 | IBM DB2/DB2 Connect Server up to 11.5.9/12.1.3 XML Column data query logic injection (EUVD-2025-206567 / Nessus ID 297628)
A vulnerability marked as problematic has been reported in IBM DB2 and DB2 Connect Server up to 11.5.9/12.1.3. Affected is an unknown function of the component XML Column Handler. The manipulation leads to improper neutralization of special elements in data query logic.
This vulnerability is traded as CVE-2025-36442. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.