IBM Db2
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*, +4 more
- >= 11.5.0, <= 11.5.9
- >= 12.1.0, <= 12.1.3
A denial-of-service vulnerability has been identified in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 for Linux, UNIX, and Windows (including DB2 Connect Server). This vulnerability allows a local user to cause a denial of service by exploiting the database monitor script, which incorrectly perceives that the instance is still in the process of starting under certain conditions.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the database instance to become unresponsive or unavailable.
Users can download a special build containing the interim fix for this issue from Fix Central. These special builds are available for Db2 versions 11.5.9, 12.1.2, and 12.1.3. Instructions for downloading these builds are available on the IBM Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.