CVE-2025-14688

Published Apr 30, 2026

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-14688 describes a vulnerability found in the CODESYS OPC UA Server. This flaw allows an unauthenticated remote attacker to gain access to sensitive information, which includes authentication details. This unauthorized access is possible when the server is configured to use the non-default Basic128Rsa15 security policy.

Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
db2

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
3.6
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

psirt@us.ibm.com
CWE-1284

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.