QID 20308
Date Published: 2023-04-06
QID 20308: IBM DB2 Denial of Service (DoS) Vulnerability (6618775)
IBM Db2 is vulnerable to a denial of service after entering a specially crafted malformed SQL statement into the db2expln tool.
Affected Versions:
Prior to 10.5 FP11 Special Build 41140
Prior to V11.1.4 FP7 Special Build 41145
Prior to 11.5 Mod 8 Fix Pack 0
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS
Successful exploitation could compromise confidentiality, integrity and availability
Solution
Please refer to the following links 6618775
Vendor References
- 6618775 -
www.ibm.com/support/pages/node/6618775
CVEs related to QID 20308
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6618775 |
|