QID 20391

Date Published: 2024-01-02

QID 20391: IBM DB2 Denial of Service (DoS) Vulnerability (7087234)

Multiple vulnerabilities in open source libraries affect IBM Db2 Federated and lead to denial of service Affected Versions:
11.1 prior to version V11.1.4 FP7
11.5 prior to version 11.5.8
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation of this vulnerability could compromise confidentiality, integrity and availability

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please refer to the following security advisory7087234 for further information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    7087234 URL Logo www.ibm.com/support/pages/node/7087234