QID 20261

Date Published: 2022-07-07

QID 20261: IBM DB2 Denial of Service (DoS) Vulnerability (6598047)

IBM Db2 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user.

Affected Versions:
IBM DB2 up to V9.7 FP11
IBM DB2 up to V10.1 FP6
IBM DB2 up to V10.5 FP11
IBM DB2 up to V11.1.4 FP 7
IBM DB2 up to 11.5 m7fp0
QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS

Note: Patch is not yet available for Release 9.7 Windows OS.

Successful exploitation may terminate server abnormally when executing specially crafted SQL statements by an authenticated user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Please refer to the following links 6598047
    Vendor References

    CVEs related to QID 20261

    Software Advisories
    Advisory ID Software Component Link
    6598047 URL Logo www.ibm.com/support/pages/node/6598047