---
id: CVE-2025-36131
title: >-
  IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through
  12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus
  command exposes user credentials to the terminal which could be obtained by a
  third party…
summary: >-
  IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through
  12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus
  command exposes user credentials to the terminal which could be obtained by a
  third party…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-359
vendor: ibm
product: db2
affected:
  - 'db2 >= 11.1.0, <= 11.1.4.7'
  - 'db2 >= 11.5.0, <= 11.5.9'
  - 'db2 >= 12.1.0, <= 12.1.3'
published: '2025-11-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36131'
references:
  - url: 'https://www.ibm.com/support/pages/node/7250484'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00173
epssPercentile: 0.06186
ingestedAt: '2026-10-07T21:54:14.981Z'
---

## Overview

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party with physical access to the system.

## Affected

- `db2 >= 11.1.0, <= 11.1.4.7`
- `db2 >= 11.5.0, <= 11.5.9`
- `db2 >= 12.1.0, <= 12.1.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
