First published: Tue Aug 13 2024(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 291307.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 Aix | >=10.5.0<=10.5.11 | |
Ibm Db2 Hp-ux | >=10.5.0<=10.5.11 | |
Ibm Db2 | >=10.5.0<=10.5.11 | |
Ibm Db2 | >=10.5.0<=10.5.11 | |
Ibm Db2 | >=10.5.0<=10.5.11 | |
Ibm Db2 Aix | >=11.1.4<=11.1.4.7 | |
Ibm Db2 Hp-ux | >=11.1.4<=11.1.4.7 | |
Ibm Db2 | >=11.1.4<=11.1.4.7 | |
Ibm Db2 | >=11.1.4<=11.1.4.7 | |
Ibm Db2 | >=11.1.4<=11.1.4.7 | |
Ibm Db2 Aix | >=11.5.0<=11.5.9 | |
Ibm Db2 Hp-ux | >=11.5.0<=11.5.9 | |
Ibm Db2 | >=11.5.0<=11.5.9 | |
Ibm Db2 | >=11.5.0<=11.5.9 | |
Ibm Db2 | >=11.5.0<=11.5.9 | |
IBM Security Verify Governance, Identity Manager software component | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager virtual appliance component | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35136 is classified as a denial of service vulnerability that can impact the availability of IBM Db2 servers.
To mitigate CVE-2024-35136, it is recommended to apply the latest patches released by IBM for affected Db2 versions.
CVE-2024-35136 affects IBM Db2 for Linux, UNIX, and Windows versions 10.5, 11.1, and 11.5 up to certain versions.
CVE-2024-35136 can lead to a denial of service condition through specially crafted queries, potentially making the database unresponsive.
Not all deployments of IBM Db2 are vulnerable; only those running specified versions under certain conditions are affected.