QID 20353

Date Published: 2023-07-24

QID 20353: IBM DB2 Denial of Service (DoS) Vulnerability (7010557)

IBM Db2 has multiple denial of service vulnerabilities with a specially crafted query

Affected Versions:
IBM DB2 10.5.0.11
IBM DB2 11.1.4.7
IBM DB2 11.5.x
QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation may lead to denial of service attack

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Please refer to the following links 7010557
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    7010557 URL Logo www.ibm.com/support/pages/node/7010557