CVE-2024-31881: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user. IBM X-Force ID: 287613.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What are the affected versions of IBM Db2 for CVE-2024-31881?
The affected versions are IBM Db2 10.5, 11.1, and 11.5.
What is the vulnerability type for CVE-2024-31881?
CVE-2024-31881 is a denial of service vulnerability.
What causes the server crash in CVE-2024-31881?
The server crash occurs when an authenticated user uses a specially crafted query on certain columnar tables.
How can I mitigate CVE-2024-31881?
Mitigation involves updating to a non-vulnerable version of IBM Db2.
What is the impact of exploiting CVE-2024-31881?
Exploiting CVE-2024-31881 can lead to a denial of service, causing the server to crash.