First published: Mon Jan 08 2024(Updated: )
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
IBM Db2 | >=10.5.0.0<=10.5.0.11 | |
IBM Db2 | >=11.1.0.0<=11.1.4.7 | |
IBM Db2 | >=11.5<=11.5.9 | |
Any of | ||
HPE HP-UX | ||
IBM AIX | ||
IBM Linux on IBM z | ||
Linux Kernel | ||
Microsoft Windows | ||
Oracle Solaris SPARC | ||
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query on Cloud Pak for Data | <=2.2 | |
IBM Watson Query on Cloud Pak for Data | <=2.1 | |
IBM Watson Query on Cloud Pak for Data | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47158 has been classified as a denial of service vulnerability allowing authenticated users to disrupt service.
To fix CVE-2023-47158, update your IBM Db2 software to the latest version beyond the affected versions, specifically 10.5.0.11, 11.1.4.7, and 11.5.9.
CVE-2023-47158 affects IBM Db2 versions 10.5, 11.1, and 11.5, specifically for Linux, UNIX, and Windows platforms.
Vulnerable systems include IBM Db2 for Linux, UNIX, and Windows in the specified versions listed for CVE-2023-47158.
No, only authenticated users with CONNECT privileges can potentially exploit CVE-2023-47158 to execute a denial of service attack.