First published: Mon Oct 16 2023(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted query statement. IBM X-Force ID: 263575.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 | >=11.5<=11.5.8 | |
Linux Linux kernel | ||
Microsoft Windows | ||
Opengroup Unix | ||
IBM IBM® Db2® | <=11.5.x | |
All of | ||
Ibm Db2 | >=11.5<=11.5.8 | |
Any of | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Opengroup Unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-40374.
The severity of CVE-2023-40374 is medium, with a severity value of 5.3.
The affected software is IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) version 11.5.x.
This vulnerability in IBM Db2 allows an attacker to cause a denial of service using a specially crafted query statement.
Yes, IBM has released a fix for this vulnerability. Please refer to the IBM Support page for further details.