QID 20365

Date Published: 2023-11-20

QID 20365: IBM DB2 Denial of Service (DoS) Vulnerability (7047261)

IBM DB2 is vulnerable to denial of service with a specially crafted query statement.

Affected Versions:
IBM DB2 11.5 prior to version V11.5.7
IBM DB2 11.5 prior to version V11.5.8

Note: This QID works based on database authentication and does not checks for the specific linux operation system.

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation could compromise confidentiality, integrity and availability

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Please refer to the following security advisory7047261 for further information.
    Vendor References

    CVEs related to QID 20365

    Software Advisories
    Advisory ID Software Component Link
    7047261 URL Logo www.ibm.com/support/pages/node/7047261