IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.
History

Fri, 07 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 18:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.
Title IBM Db2 improper account lockout
First Time appeared Ibm
Ibm db2
Weaknesses CWE-324
CPEs cpe:2.3:a:ibm:db2:10.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:10.5.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.1.4.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-11-07T18:38:29.123Z

Updated: 2025-11-07T18:56:16.588Z

Reserved: 2025-04-15T09:48:51.519Z

Link: CVE-2025-33012

cve-icon Vulnrichment

Updated: 2025-11-07T18:56:02.860Z

cve-icon NVD

Status : Received

Published: 2025-11-07T19:15:46.940

Modified: 2025-11-07T19:15:46.940

Link: CVE-2025-33012

cve-icon Redhat

No data.