CVE-2023-29258: IBM Db2 denial of service
Published Dec 4, 2023
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted federated query on specific federation objects. IBM X-Force ID: 252048.
Affected Software
7 affected components
IBM IBM® Db2®<=11.1.4.x
IBM IBM® Db2®<=11.5.x
All of the following
Any of the following
IBM DB2>=11.1.0.0<=11.1.4.7
IBM DB2>=11.5<=11.5.9
Any of the following
Linux Linux kernel
Microsoft Windows
Opengroup Unix
Event History
Dec 4, 2023
CVE Published
01:12 AM
Data Sourced
01:12 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this IBM Db2 vulnerability?
The vulnerability ID for this IBM Db2 vulnerability is CVE-2023-29258.
2
What is the severity of CVE-2023-29258?
The severity of CVE-2023-29258 is medium with a CVSS score of 5.3.
3
Which versions of IBM Db2 are affected by CVE-2023-29258?
IBM Db2 versions 11.1.4.x and 11.5.x are affected by CVE-2023-29258.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through a specially crafted federated query on specific federation objects.
5
Is there a fix available for CVE-2023-29258?
Refer to IBM's official support page for information on available fixes and patches.