First published: Mon Jan 08 2024(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270264.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
IBM Db2 | <11.5.9 | |
Any of | ||
IBM AIX | ||
IBM Linux on IBM z | ||
Linux Kernel | ||
Microsoft Windows | ||
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.2 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.1 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47141 is categorized as a denial of service vulnerability impacting IBM DB2 for Linux, UNIX, and Windows.
To remediate CVE-2023-47141, upgrade IBM DB2 to version 11.5.9 or later to eliminate the vulnerability.
CVE-2023-47141 affects authenticated users with CONNECT privileges on IBM DB2 for Linux, UNIX, and Windows versions prior to 11.5.9.
CVE-2023-47141 allows attackers to craft a query that can cause a denial of service condition in the affected IBM DB2 software.
Currently, the recommended approach for CVE-2023-47141 is to apply the available software update instead of relying on a workaround to mitigate the issue.