CVE-2021-29702: High severity ibm db2 universal database vulnerability
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
Other sources
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-29702?
CVE-2021-29702 is a vulnerability in Db2 for Linux, UNIX and Windows that allows an attacker to launch a denial of service attack by executing a specially crafted SELECT statement.
Which versions of Db2 for Linux, UNIX and Windows are affected by CVE-2021-29702?
Db2 versions 11.1.4 and 11.5.5 are affected by CVE-2021-29702.
What is the severity of CVE-2021-29702?
CVE-2021-29702 has a severity rating of 7.5 (high).
Is IBM AIX vulnerable to CVE-2021-29702?
No, IBM AIX is not vulnerable to CVE-2021-29702.
Is Linux Linux kernel vulnerable to CVE-2021-29702?
No, Linux Linux kernel is not vulnerable to CVE-2021-29702.
Is Microsoft Windows vulnerable to CVE-2021-29702?
No, Microsoft Windows is not vulnerable to CVE-2021-29702.
How can I fix CVE-2021-29702?
IBM has released patches and updates for Db2 to address the vulnerability. It is recommended to update to the latest version of Db2.