CVE-2023-46167: IBM Db2 denial of service
Published Dec 1, 2023
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 269367.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) federated server is vulnerable to a denial of service when a specially crafted cursor is used.
— IBM
Affected Software
5 affected components
IBM IBM® Db2®<=11.5.6 through 11.5.8
All of the following
IBM DB2>=11.5.6<=11.5.8
Any of the following
Linux Linux kernel
Microsoft Windows
Opengroup Unix
Event History
Dec 1, 2023
CVE Published
via IBM·12:00 AM
Dec 4, 2023
CVE Published
via MITRE·12:04 AM
Data Sourced
via MITRE·12:04 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the IBM Db2 denial of service vulnerability?
The vulnerability ID is CVE-2023-46167.
2
What is the severity of CVE-2023-46167?
The severity of CVE-2023-46167 is medium.
3
Which software versions are affected by CVE-2023-46167?
IBM Db2 versions 11.5.6 through 11.5.8 are affected by CVE-2023-46167.
4
How can the IBM Db2 denial of service vulnerability be exploited?
The vulnerability can be exploited by using a specially crafted cursor.
5
Is there a patch or fix available for CVE-2023-46167?
Yes, IBM has provided a fix for the vulnerability. Please refer to the IBM support page for more information.