First published: Mon Jan 08 2024(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database to cause a denial of service when a statement is run on columnar tables. IBM X-Force ID: 273393.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data | <=2.2 | |
IBM Watson Query with Cloud Pak for Data | <=2.1 | |
IBM Watson Query with Cloud Pak for Data | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 | |
All of | ||
IBM Db2 | <11.5.9 | |
Any of | ||
IBM AIX | ||
IBM z/OS Linux | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50308 has been classified as a denial of service vulnerability affecting IBM Db2 version 11.5.
To mitigate CVE-2023-50308, it is recommended to apply the latest patches or updates provided by IBM for Db2 version 11.5.
CVE-2023-50308 affects authenticated users of IBM Db2 for Linux, UNIX, and Windows version 11.5, particularly when running certain statements on columnar tables.
Vulnerable systems include IBM Db2 for Linux, UNIX, and Windows with versions up to 11.5.9.
CVE-2023-50308 can cause a denial of service, which may lead to disruptions in database availability.