« Volver al listado

CVE-2025-33130

Estado: AnalizadaMedia (6.5)—

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-33130",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-33130",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-17T19:50:18.284060Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2_merge_backup_for_linux_unix_and_windows:12.1.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "DB2 Merge Backup for Linux, UNIX and Windows",
          "versions": [
            {
              "status": "affected",
              "version": "12.1.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "2.1.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-02-17T20:22:03.723",
  "references": [
    {
      "url": "https://www.ibm.com/support/pages/node/7260043",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack."
    },
    {
      "lang": "es",
      "value": "IBM DB2 Merge Backup para Linux, UNIX y Windows 12.1.0.0 podría permitir a un usuario autenticado provocar que el programa falle debido a la sobrescritura de un búfer cuando se asigna en la pila."
    }
  ],
  "lastModified": "2026-06-17T09:13:09.983",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:db2_merge_backup:12.1.0.0:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4819D3E-34CC-4D0A-9BC5-3B0B2FF287C0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:db2_merge_backup:12.1.0.0:*:*:*:*:unix:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80F6A623-364C-4E5A-A20B-58F30FE1EF5F"
            },
            {
              "criteria": "cpe:2.3:a:ibm:db2_merge_backup:12.1.0.0:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F54A9A5-0C7C-42A3-87C6-0DF353E88CD2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}