First published: Tue Aug 13 2024(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 292639.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =11.5.8 | |
IBM Db2 | =11.5.8 | |
IBM Db2 | =11.5.8 | |
IBM Db2 | =11.5.9 | |
IBM Db2 | =11.5.9 | |
IBM Db2 | =11.5.9 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35152 is classified as a medium severity vulnerability that can lead to a denial of service.
To mitigate CVE-2024-35152, it is recommended to update IBM Db2 to the latest version as per IBM's guidance.
CVE-2024-35152 affects IBM Db2 versions 11.5.8 and 11.5.9 on Linux, UNIX, and Windows.
CVE-2024-35152 can be exploited by an authenticated user through specially crafted queries.
The impact of CVE-2024-35152 is a potential denial of service, which can disrupt the availability of the affected systems.