IBM Product Security Update Advisory
Overview
We have released a security update to fix vulnerabilities in IBM products. users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-12985
License Service Version: 4.2.18 or earlier
CVE-2025-36184
IBM Db2 Version: 11.5.0 or later and 11.5.9 or earlier
CVE-2025-36384
IBM Db2 versions: 12.1.0 or later and 12.1.3 or earlier
Resolved Vulnerabilities
Privilege escalation vulnerability in the /etc/passwd file in the License Service (CVE-2025-12985)
Local privilege escalation vulnerability in IBM Db2 (CVE-2025-36184)
Privilege escalation vulnerability due to the use of unquoted search paths in IBM Db2 (CVE-2025-36384)
Vulnerability Patches
vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-12985
License Service Version: 4.2.18
CVE-2025-36184
IBM Db2 versions: Apply builds from Referenced Sites[2]
CVE-2025-36384
IBM Db2 version: Apply Builds with Referenced Sites[3]
referenced Sites
[1] License Service: Privilege escalation vulnerability
https://www.ibm.com/support/pages/license-service-privilege-escalation-vulnerability
[2] Security Bulletin: IBM® Db2® is vulnerable to Local Privilege Escalation and get root access to the system (CVE-2025-36184)
https://www.ibm.com/support/pages/node/7257519
[3] Security Bulletin: IBM® Db2® is vulnerable to privilege escalation due to the use of an unquoted search path element (CVE-2025-36384)
https://www.ibm.com/support/pages/node/7257678