---
id: CVE-2025-36372
title: >-
  IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and
  Windows (includes Db2 Connect Server) could disclose sensitive information to
  an authenticated user from the monitoring and event tables.
summary: >-
  IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and
  Windows (includes Db2 Connect Server) could disclose sensitive information to
  an authenticated user from the monitoring and event tables.
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-538
vendor: ibm
product: db2
affected:
  - 'db2 >= 11.5.0, < 11.5.9'
  - 'db2 >= 12.1.0, <= 12.1.4'
patched:
  - db2 11.5.9
published: '2026-06-30'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36372'
references:
  - url: 'https://www.ibm.com/support/pages/node/7277417'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00303
epssPercentile: 0.20681
ingestedAt: '2026-09-29T19:44:04.097Z'
---

## Overview

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.

## Affected

- `db2 >= 11.5.0, < 11.5.9`
- `db2 >= 12.1.0, <= 12.1.4`

## Remediation

Upgrade past the affected range:

- `db2 11.5.9`
