CVE-2023-40372: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement using External Tables. IBM X-Force ID: 263499.
Other sources
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted SQL statement using External Tables.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-40372.
What software is affected by this vulnerability?
IBM DB2 for Linux UNIX and Windows (includes Db2 Connect Server) version 11.5.x is affected by this vulnerability.
What is the severity of CVE-2023-40372?
The severity of CVE-2023-40372 is medium with a severity value of 5.3.
How can the vulnerability be exploited?
The vulnerability can be exploited by using a specially crafted SQL statement using External Tables.
Is there a fix available for this vulnerability?
Yes, IBM has provided a fix for this vulnerability. Please refer to the IBM support pages for more information.