IBM Product Security Update Advisory

IBM Product Security Update Advisory

Overview

 

We have released a security update to fix vulnerabilities in IBM products. users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-12985

 

License Service Version: 4.2.18 or earlier

 

CVE-2025-36184

 

IBM Db2 Version: 11.5.0 or later and 11.5.9 or earlier

 

CVE-2025-36384

 

IBM Db2 versions: 12.1.0 or later and 12.1.3 or earlier

 

 

Resolved Vulnerabilities

 

Privilege escalation vulnerability in the /etc/passwd file in the License Service (CVE-2025-12985)
Local privilege escalation vulnerability in IBM Db2 (CVE-2025-36184)
Privilege escalation vulnerability due to the use of unquoted search paths in IBM Db2 (CVE-2025-36384)

 

 

Vulnerability Patches

vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-12985

 

License Service Version: 4.2.18

 

CVE-2025-36184

 

IBM Db2 versions: Apply builds from Referenced Sites[2]

 

CVE-2025-36384

 

IBM Db2 version: Apply Builds with Referenced Sites[3]

 

 

referenced Sites

 

[1] License Service: Privilege escalation vulnerability
https://www.ibm.com/support/pages/license-service-privilege-escalation-vulnerability
[2] Security Bulletin: IBM® Db2® is vulnerable to Local Privilege Escalation and get root access to the system (CVE-2025-36184)
https://www.ibm.com/support/pages/node/7257519
[3] Security Bulletin: IBM® Db2® is vulnerable to privilege escalation due to the use of an unquoted search path element (CVE-2025-36384)
https://www.ibm.com/support/pages/node/7257678