First published: Tue Aug 13 2024(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287614.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | >=11.1.4<=11.1.4.7 | |
IBM Db2 | >=11.1.4<=11.1.4.7 | |
IBM Db2 | >=11.1.4<=11.1.4.7 | |
IBM Db2 | >=11.5.0<=11.5.9 | |
IBM Db2 | >=11.5.0<=11.5.9 | |
IBM Db2 | >=11.5.0<=11.5.9 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31882 is classified as a denial of service vulnerability that can lead to the server crashing.
To mitigate CVE-2024-31882, review and update the affected versions of IBM Db2 to the latest available patches.
CVE-2024-31882 impacts IBM Db2 versions 11.1.0 and 11.5.0 up to 11.1.4.7 and 11.5.9 respectively.
No, CVE-2024-31882 requires authentication for exploitation through a specially crafted SQL statement.
The potential impact of CVE-2024-31882 includes service interruption and a crash of the IBM Db2 server.