IBM Db2
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*, +4 more
- >= 11.5.0, <= 11.5.9
- >= 12.1.0, <= 12.1.2
A denial-of-service vulnerability has been identified in IBM Db2 for Linux, UNIX, and Windows, including DB2 Connect Server, versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. This vulnerability could allow a local user to cause a denial-of-service condition by copying large tables containing XML data, due to improper resource allocation.
Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or unavailable.
Users can download a special build containing the interim fix for this issue from Fix Central. For Db2 version 11.5, the special build #66394 or later is available. For Db2 version 12.1, the special build #72296 or later is available. Instructions for downloading these special builds can be found on the IBM Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.