PT-2024-4311 · Ibm · Ibm Db2

Published

2024-06-12

·

Updated

2024-08-07

·

CVE-2024-31881

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) versions 10.5, 11.1, and 11.5
Description The issue is related to a denial of service that may occur when a specially crafted query is used on certain columnar tables by an authenticated user, potentially causing the server to crash. This is due to unlimited resource allocation.
Recommendations For versions 10.5, 11.1, and 11.5, consider restricting access to certain columnar tables to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider limiting the use of specially crafted queries on the affected tables until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2024-04799
CVE-2024-31881

Affected Products

Ibm Db2