First published: Wed Jul 01 2020(Updated: )
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) is vulnerable to a denial of service, caused by improper handling of Secure Sockets Layer (SSL) renegotiation requests. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to increase the resource usage on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.7.0.0 | |
IBM Db2 | =10.1.0.0 | |
IBM Db2 | =10.5.0.0 | |
IBM Db2 | =11.1.0.0 | |
IBM Db2 | =11.5.0.0 | |
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4355 has a severity rating of Medium due to its potential for causing a denial of service.
To fix CVE-2020-4355, you should apply the latest security updates provided by IBM for the affected versions of DB2.
CVE-2020-4355 affects IBM DB2 versions 9.7.0.0, 10.1.0.0, 10.5.0.0, 11.1.0.0, and 11.5.0.0.
CVE-2020-4355 can be exploited through remote attacks leveraging specially-crafted SSL renegotiation requests.
CVE-2020-4355 is not limited to any specific operating system but affects the listed versions of IBM DB2 running on Linux, UNIX, and Windows.