PT-2026-51295 · Ibm · Db2 On Cloud Pak For Data/Db2 Warehouse On Cloud Pak For Data

Published

2026-06-22

·

Updated

2026-06-22

·

CVE-2025-2669

CVSS v3.1

6.0

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2669

Affected Products

Db2 On Cloud Pak For Data/Db2 Warehouse On Cloud Pak For Data