CVE-2024-47118: IBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 10.5to a version that resolves this vulnerability.Fixed in 10.5.11Patch DT398093 - Upgrade
Upgrade
IBM Db2 11.1to a version that resolves this vulnerability.Fixed in 11.1.4.7Patch DT398093 - Upgrade
Upgrade
IBM Db2 11.5to a version that resolves this vulnerability.Fixed in 11.5.9Patch Special Build #69673 or later - Upgrade
Upgrade
IBM Db2 12.1to a version that resolves this vulnerability.Fixed in 12.1.3Patch DT398093 - Upgrade
Upgrade
IBM Db2 12.1.2to a version that resolves this vulnerability.Patch Special Build #70120 or later
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47118?
CVE-2024-47118 is rated as a denial of service vulnerability, which can cause the IBM Db2 server to crash.
How do I fix CVE-2024-47118?
To mitigate CVE-2024-47118, it is recommended to apply the latest patches provided by IBM for affected versions of Db2.
What versions of IBM Db2 are affected by CVE-2024-47118?
CVE-2024-47118 affects IBM Db2 versions 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3.
What can trigger the denial of service in CVE-2024-47118?
CVE-2024-47118 can be triggered by executing a specially crafted query that leads to a crash of the IBM Db2 server.
Is there a workaround for CVE-2024-47118?
Currently, there are no known workarounds for CVE-2024-47118, and the best course of action is to update to a secure version.