
A severe vulnerability was disclosed for IBM DB2 (CVE-2025-36384) https://vuldb.com/?id.343553
Post summary
A severe vulnerability in IBM DB2 (CVE‑2025‑36384) has been publicly disclosed, with details available on vuldb.com.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-01-30 | 2 | Disclosure2 |
| 2026-01-31 | 2 | Disclosure2 |
| 2026-02-05 | 1 | General1 |

A severe vulnerability was disclosed for IBM DB2 (CVE-2025-36384) https://vuldb.com/?id.343553
Post summary
A severe vulnerability in IBM DB2 (CVE‑2025‑36384) has been publicly disclosed, with details available on vuldb.com.

⚠️ Vulnerabilidades en productos IBM ❗ CVE-2025-36384 ❗ CVE-2025-36184 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ibm-3/ https://t.co/INsWaIExTt
Post summary
The tweet lists two IBM product CVEs and links to an external site for additional information, without providing specifics on the vulnerability, exploitation, or remediation.

CVE-2025-36384 Local Privilege Escalation in IBM Db2 for Windows via Unquoted Search Path https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-36384
Post summary
The post discloses CVE-2025-36384, describing a local privilege escalation issue in IBM Db2 for Windows caused by an unquoted search path; it provides no PoC, exploit, patch, or evidence of active exploitation.

🟠 CVE-2025-36384 - High IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element. https://www.thehackerwire.com/vulnerability/CVE-2025-36384/ https://t.co/mQ89Fd55Ir
Post summary
IBM Db2 for Windows versions 12.1.0 to 12.1.3 are vulnerable to a local privilege escalation through an unquoted search path element, as described in the CVE-2025-36384 announcement, with no reported exploitation or patch information.

CVE-2025-36384 IBM Db2 for Windows could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element. https://www.cve.org/CVERecord?id=CVE-2025-36384
Post summary
IBM Db2 for Windows contains a privilege‑elevation flaw where a local user with filesystem access can exploit an unquoted search path element to gain higher privileges.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | ibm | db2 | - | windows | - |