QID 20247

Date Published: 2022-04-06

QID 20247: IBM DB2 Denial of Service (DoS) Vulnerability (6466371)

DB2 is a family of data management products, including database servers, developed by IBM.

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement.

Affected Versions:
IBM DB2 Prior to V10.1 FP6
IBM DB2 Prior to V10.5 FP11
IBM DB2 Prior to V11.1 FP6
IBM DB2 Prior to v11.5.5 FP1
IBM DB2 Prior to V11.5 M6FP0 0

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable version of DB2 on windows OS

Successful exploitation could allow attacker to terminate server abnormally by executing denial of service attack

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Please refer to the following links 6466371

    Vendor References

    CVEs related to QID 20247

    Software Advisories
    Advisory ID Software Component Link
    6466371 URL Logo www.ibm.com/support/pages/node/6466371