First published: Tue Jun 11 2024(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Ibm Db2 | >=10.5.0.0<=10.5.11 | |
Ibm Db2 | >=11.1.4<=11.1.4.7 | |
Ibm Db2 | >=11.5<=11.5.9 | |
Any of | ||
Linux Kernel | ||
Microsoft Windows | ||
opengroup Unix | ||
IBM DB2 pureScale Feature | <=10.5.0 - 10.5.11 | |
IBM DB2 pureScale Feature | <=11.1.4 - 11.1.4.7 | |
IBM DB2 pureScale Feature | <=11.5.0 - 11.5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31880 is classified as a denial of service vulnerability affecting specific versions of IBM Db2.
To fix CVE-2024-31880, update IBM Db2 to the latest version that addresses this vulnerability.
CVE-2024-31880 affects IBM Db2 versions 10.5, 11.1, and 11.5 under specific configurations.
No, CVE-2024-31880 can only be exploited by authenticated users using a specially crafted SQL statement.
CVE-2024-31880 can lead to a denial of service, causing the IBM Db2 server to crash.