QID 20351
Date Published: 2023-06-05
QID 20351: IBM DB2 Denial of Service (DoS) Vulnerability (6985683)
IBM Db2 is vulnerable to a denial of service as the server may crash when when attempting to use ACR client affinity for unfenced DRDA federation wrappers.
Affected Versions:
IBM DB2 11.5 prior to version V11.5.7
IBM DB2 11.5 prior to version V11.5.8
Note: the configurations cannot be checked hence potential detection
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS
Successful exploitation may lead to denial of service
Solution
Please refer to the following links 6985683
Vendor References
- 6985683 -
www.ibm.com/support/pages/node/6985683
CVEs related to QID 20351
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6985683 |
|