QID 20375
Date Published: 2023-11-21
QID 20375: IBM DB2 Denial of Service (DoS) Vulnerability (7047563)
IBM Db2 is vulnerable to denial of service with a specially crafted query containing common table expressions.
Affected Versions:
10.5 prior to version 10.5 FP11
11.1 prior to version 11.1.4 FP7
11.5 prior to version 11.5.7
11.5 prior to version 11.5.8
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common table expressions.
Solution
Please refer to the following security advisory7047563 for further information.
Vendor References
- 7047563 -
www.ibm.com/support/pages/node/7047563
CVEs related to QID 20375
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7047563 |
|