PT-2022-22935 · Ibm · Ibm Db2

Published

2022-09-13

·

Updated

2023-09-21

·

CVE-2022-35637

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Db2 for Linux, UNIX and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5
Description The issue allows for a denial of service after entering a malformed SQL statement into the Db2expln tool.
Recommendations For IBM Db2 for Linux, UNIX and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5, consider restricting access to the Db2expln tool to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-35637

Affected Products

Ibm Db2