CVE-2025-33012

MEDIUM

IBM Db2 <12.1.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7250469

Scores

CVSS v3 6.3
EPSS 0.0002
EPSS Percentile 6.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-324
Status published
Products (1)
ibm/db2 10.5.0.0 - 10.5.0.11
Published Nov 07, 2025
Tracked Since Feb 18, 2026