CVE-2023-47158: IBM Db2 denial of service
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server)
10.5, 11.1 and 11.5
could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47158?
CVE-2023-47158 has been classified as a denial of service vulnerability allowing authenticated users to disrupt service.
How do I fix CVE-2023-47158?
To fix CVE-2023-47158, update your IBM Db2 software to the latest version beyond the affected versions, specifically 10.5.0.11, 11.1.4.7, and 11.5.9.
Who is affected by CVE-2023-47158?
CVE-2023-47158 affects IBM Db2 versions 10.5, 11.1, and 11.5, specifically for Linux, UNIX, and Windows platforms.
What types of systems are vulnerable to CVE-2023-47158?
Vulnerable systems include IBM Db2 for Linux, UNIX, and Windows in the specified versions listed for CVE-2023-47158.
Can an unauthenticated user exploit CVE-2023-47158?
No, only authenticated users with CONNECT privileges can potentially exploit CVE-2023-47158 to execute a denial of service attack.