PT-2024-24265 · Ibm · Ibm Db2

Published

2024-08-14

·

Updated

2024-09-21

·

CVE-2024-31882

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) versions 11.1 and 11.5
Description The issue is a denial of service under specific non-default configurations, where the server may crash when using a specially crafted SQL statement by an authenticated user.
Recommendations For versions 11.1 and 11.5, upgrade the affected components to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the SQL statement functionality until a patch is available. Avoid using specially crafted SQL statements in the affected IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) versions until the issue is resolved.

Fix

DoS

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-31882

Affected Products

Ibm Db2