CVE-2023-30449: IBM Db2 denial of service
Published Jul 7, 2023
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439.
Affected Software
19 affected components
IBM IBM® Db2®<=10.5.0.11
IBM IBM® Db2®<=11.1.4.7
IBM IBM® Db2®<=11.5.x
All of the following
Any of the following
IBM DB2=10.5.0.11
IBM DB2=11.1.4.7
IBM DB2=11.5
Any of the following
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
IBM DB2=10.5.0.11
IBM DB2=11.1.4.7
IBM DB2=11.5
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Jul 7, 2023
CVE Published
via IBM·12:00 AM
Jul 8, 2023
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionSeverityWeakness
Jul 10, 2023
Data Sourced
04:15 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this IBM Db2 vulnerability?
The vulnerability ID for this IBM Db2 vulnerability is CVE-2023-30449.
2
What is the severity of CVE-2023-30449?
The severity of CVE-2023-30449 is high with a severity value of 7.
3
Which versions of IBM Db2 are affected by CVE-2023-30449?
IBM Db2 versions 10.5, 11.1, and 11.5 are affected by CVE-2023-30449.
4
What is the impact of CVE-2023-30449?
CVE-2023-30449 can cause denial of service with a specially crafted query.
5
Are Linux, HP-UX, IBM AIX, Microsoft Windows, and Oracle Solaris vulnerable to CVE-2023-30449?
No, Linux, HP-UX, IBM AIX, Microsoft Windows, and Oracle Solaris are not vulnerable to CVE-2023-30449.