CVE-2025-2669
Received
Received - Intake
IBM Db2 Cloud Pak Data Token Validation Flaw
Publication date: 2026-06-22
Last updated on: 2026-06-22
Assigner: IBM Corporation
Description
Description
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | db2_on_cloud_pak_for_data | From 4.8 (inc) to 5.3 (inc) |
| ibm | db2_warehouse_on_cloud_pak_for_data | From 4.8 (inc) to 5.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |