A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bloomberg
Bloomberg comdb2 |
|
| CPEs | cpe:2.3:a:bloomberg:comdb2:8.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Bloomberg
Bloomberg comdb2 |
Wed, 23 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability. | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: talos
Published: 2025-07-22T15:26:29.880Z
Updated: 2025-11-03T19:54:05.440Z
Reserved: 2025-05-22T16:04:46.441Z
Link: CVE-2025-36512
Updated: 2025-11-03T19:54:05.440Z
Status : Modified
Published: 2025-07-22T16:15:27.117
Modified: 2025-11-03T20:18:30.500
Link: CVE-2025-36512
No data.