CVE-2023-29258: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted federated query on specific federation objects. IBM X-Force ID: 252048.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service through a specially crafted federated query on specific federation objects.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Db2 vulnerability?
The vulnerability ID for this IBM Db2 vulnerability is CVE-2023-29258.
What is the severity of CVE-2023-29258?
The severity of CVE-2023-29258 is medium with a CVSS score of 5.3.
Which versions of IBM Db2 are affected by CVE-2023-29258?
IBM Db2 versions 11.1.4.x and 11.5.x are affected by CVE-2023-29258.
How can this vulnerability be exploited?
This vulnerability can be exploited through a specially crafted federated query on specific federation objects.
Is there a fix available for CVE-2023-29258?
Refer to IBM's official support page for information on available fixes and patches.