CVE-2024-27254: IBM Db2 for Linux, UNIX and Windows denial of service
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server is vulnerable to denial of service with a specially crafted query under certain conditions.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27254?
The severity of CVE-2024-27254 is classified as a denial of service vulnerability.
How do I fix CVE-2024-27254?
To fix CVE-2024-27254, ensure your IBM Db2 version is updated to the latest patches provided by IBM.
Which products are affected by CVE-2024-27254?
CVE-2024-27254 affects IBM Db2 versions 10.5, 11.1, and 11.5 across Linux, UNIX, and Windows platforms.
What type of attack is CVE-2024-27254 associated with?
CVE-2024-27254 is associated with a denial of service attack triggered by a specially crafted query.
Is CVE-2024-27254 applicable to IBM Db2 on Cloud Pak for Data?
Yes, CVE-2024-27254 is applicable to IBM Db2 on Cloud Pak for Data as well as Db2 Warehouse on Cloud Pak for Data.