CVE-2021-29703: High severity ibm db2 universal database vulnerability
Published Jun 24, 2021
·Updated
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement.
Affected Software
10 affected components
IBM DB2=9.7
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=11.1
IBM DB2=11.5
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Jun 24, 2021
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via IBM·10:22 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-29703?
The severity of CVE-2021-29703 is high with a severity value of 7.5.
2
Which version of Db2 is affected by CVE-2021-29703?
Db2 versions 9.7, 10.1, 10.5, 11.1, and 11.5 are affected by CVE-2021-29703.
3
What is the vulnerability description of CVE-2021-29703?
CVE-2021-29703 is a denial of service vulnerability in Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) where the server terminates abnormally when executing a specially crafted SELECT statement.
4
Is IBM Db2 vulnerable to CVE-2021-29703?
Yes, IBM Db2 versions 9.7, 10.1, 10.5, 11.1, and 11.5 are vulnerable to CVE-2021-29703.
5
Where can I find more information about CVE-2021-29703?
More information about CVE-2021-29703 can be found on the IBM X-Force ID: 200659 page and IBM Support page.