SB20260216152 - Multiple vulnerabilities in IBM Db2 Intelligence Center



SB20260216152 - Multiple vulnerabilities in IBM Db2 Intelligence Center

Published: February 16, 2026

Security Bulletin ID SB20260216152
Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 75% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2025-47913)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when handling SSH_AGENT_SUCCESS responses in ssh agent. A malicious server can send a specially crafted response to the ssh client and crash it. 


2) Incorrect Regular Expression (CVE-ID: CVE-2022-25927)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation passed via the trim() function. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


3) Resource exhaustion (CVE-ID: CVE-2025-6493)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in the functionality of the file mode/markdown/markdown.js of the component Markdown Mode. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


4) Client-Side Enforcement of Server-Side Security (CVE-ID: CVE-2025-14687)

The vulnerability allows a remote user to perform unauthorized actions.

The vulnerability exists due to client-side enforcement of sever side security mechanisms. A remote user can perform unauthorized actions.


Remediation

Install update from vendor's website.