CVE-2024-35136: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 291307.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35136?
CVE-2024-35136 is classified as a denial of service vulnerability that can impact the availability of IBM Db2 servers.
How do I fix CVE-2024-35136?
To mitigate CVE-2024-35136, it is recommended to apply the latest patches released by IBM for affected Db2 versions.
Which versions of IBM Db2 are affected by CVE-2024-35136?
CVE-2024-35136 affects IBM Db2 for Linux, UNIX, and Windows versions 10.5, 11.1, and 11.5 up to certain versions.
What impact does CVE-2024-35136 have on IBM Db2?
CVE-2024-35136 can lead to a denial of service condition through specially crafted queries, potentially making the database unresponsive.
Are all deployments of IBM Db2 vulnerable to CVE-2024-35136?
Not all deployments of IBM Db2 are vulnerable; only those running specified versions under certain conditions are affected.