PT-2024-24265 · Ibm · Ibm Db2
Published
2024-08-14
·
Updated
2024-09-21
·
CVE-2024-31882
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) versions 11.1 and 11.5
Description
The issue is a denial of service under specific non-default configurations, where the server may crash when using a specially crafted SQL statement by an authenticated user.
Recommendations
For versions 11.1 and 11.5, upgrade the affected components to a newer version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the SQL statement functionality until a patch is available.
Avoid using specially crafted SQL statements in the affected IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) versions until the issue is resolved.
Fix
DoS
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Db2