CVE Vulnerabilities

CVE-2025-33012

Use of a Key Past its Expiration Date

Published: Nov 07, 2025 | Modified: Nov 19, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

Weakness

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Affected Software

Name Vendor Start Version End Version
Db2 Ibm 10.5.0.0 (including) 10.5.0.11 (including)
Db2 Ibm 11.1.0 (including) 11.1.4.7 (including)
Db2 Ibm 11.5.0 (including) 11.5.9 (including)
Db2 Ibm 12.1.0 (including) 12.1.3 (including)

Potential Mitigations

References