First published: Wed Aug 14 2024(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 294295.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 Aix | >=11.1.4<=11.1.4.7 | |
Ibm Db2 | >=11.1.4<=11.1.4.7 | |
Ibm Db2 | >=11.1.4<=11.1.4.7 | |
Ibm Db2 | >=11.1.4<=11.1.4.7 | |
Ibm Db2 Aix | >=11.5.0<=11.5.9 | |
Ibm Db2 | >=11.5.0<=11.5.9 | |
Ibm Db2 | >=11.5.0<=11.5.9 | |
Ibm Db2 | >=11.5.0<=11.5.9 | |
IBM Security Verify Governance, Identity Manager software component | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager virtual appliance component | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37529 has been classified as a denial of service vulnerability due to improper memory allocation.
To mitigate CVE-2024-37529, it is recommended to apply the latest security patches provided by IBM for affected Db2 versions.
CVE-2024-37529 affects IBM Db2 versions 11.1, 11.5, and specific subversions up to 11.1.4.7 and 11.5.9.
No, CVE-2024-37529 requires an authenticated user to exploit the vulnerability.
CVE-2024-37529 could allow an authenticated user to create a denial of service condition through a specially crafted query.