CVE-2023-52296: IBM Db2 for Linux, UNIX and Windows denial of service
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently. IBM X-Force ID: 278547.
Other sources
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service when quering a specific UDF built-in function concurrently.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52296?
CVE-2023-52296 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2023-52296?
To fix CVE-2023-52296, users should apply the recommended patches provided by IBM for their affected Db2 installations.
Which versions of IBM Db2 are affected by CVE-2023-52296?
CVE-2023-52296 affects IBM Db2 version 11.5 on Linux, UNIX, and Windows platforms.
What type of vulnerability is CVE-2023-52296?
CVE-2023-52296 is a denial of service vulnerability that arises when querying a specific UDF built-in function simultaneously.
Is there a workaround for CVE-2023-52296?
As of now, IBM has not provided specific workarounds for CVE-2023-52296, so applying patches is the primary mitigation strategy.