CVE-2023-27559: IBM Db2 denial of service
Published Apr 26, 2023
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted subquery. IBM X-Force ID: 249196.
Other sources
IBM Db2 is vulnerable to a denial of service as the server may crash when using a specially crafted subquery.
— IBM
Affected Software
49 affected components
IBM Cloud Pak for Business Automation<=V22.0.2 - V22.0.2-IF004
IBM Cloud Pak for Business Automation<=V21.0.3 - V21.0.3-IF020
IBM Cloud Pak for Business Automation<=V22.0.1 - V22.0.1-IF006 and later fixesV21.0.2 - V21.0.2-IF012 and later fixesV21.0.1 - V21.0.1-IF007 and later fixesV20.0.1 - V20.0.3 and later fixesV19.0.1 - V19.0.3 and later fixesV18.0.0 - V18.0.2 and later fixes
All of the following
Any of the following
IBM DB2>=11.1<11.1.4
IBM DB2>=11.5<11.5.8
IBM DB2=10.5
IBM DB2=10.5-fp1
IBM DB2=10.5-fp10
IBM DB2=10.5-fp2
IBM DB2=10.5-fp3
IBM DB2=10.5-fp3a
IBM DB2=10.5-fp4
IBM DB2=10.5-fp5
IBM DB2=10.5-fp6
IBM DB2=10.5-fp7
IBM DB2=10.5-fp8
IBM DB2=10.5-fp9
IBM DB2=11.1.4
IBM DB2=11.1.4-fp1
IBM DB2=11.1.4-fp2
IBM DB2=11.1.4-fp3
IBM DB2=11.1.4-fp4
IBM DB2=11.1.4-fp5
IBM DB2=11.1.4-fp6
Any of the following
Linux Linux kernel
Microsoft Windows
IBM DB2>=11.1<11.1.4
IBM DB2>=11.5<11.5.8
IBM DB2=10.5
IBM DB2=10.5-fp1
IBM DB2=10.5-fp10
IBM DB2=10.5-fp2
IBM DB2=10.5-fp3
IBM DB2=10.5-fp3a
IBM DB2=10.5-fp4
IBM DB2=10.5-fp5
IBM DB2=10.5-fp6
IBM DB2=10.5-fp7
IBM DB2=10.5-fp8
IBM DB2=10.5-fp9
IBM DB2=11.1.4
IBM DB2=11.1.4-fp1
IBM DB2=11.1.4-fp2
IBM DB2=11.1.4-fp3
IBM DB2=11.1.4-fp4
IBM DB2=11.1.4-fp5
IBM DB2=11.1.4-fp6
Linux Linux kernel
Microsoft Windows
Event History
Apr 26, 2023
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-27559.
2
What is the severity of CVE-2023-27559?
The severity of CVE-2023-27559 is high.
3
Which software versions are affected by CVE-2023-27559?
IBM Db2 for Linux, UNIX, and Windows versions 10.5, 11.1, and 11.5 are affected by CVE-2023-27559.
4
How can I fix CVE-2023-27559?
Apply the necessary patches or updates provided by IBM to fix CVE-2023-27559.
5
Is Linux Linux kernel or Microsoft Windows affected by CVE-2023-27559?
No, Linux Linux kernel and Microsoft Windows are not affected by CVE-2023-27559.