CVE-2024-35152: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 292639.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35152?
CVE-2024-35152 is classified as a medium severity vulnerability that can lead to a denial of service.
How do I fix CVE-2024-35152?
To mitigate CVE-2024-35152, it is recommended to update IBM Db2 to the latest version as per IBM's guidance.
Which versions of IBM Db2 are affected by CVE-2024-35152?
CVE-2024-35152 affects IBM Db2 versions 11.5.8 and 11.5.9 on Linux, UNIX, and Windows.
Who can exploit CVE-2024-35152?
CVE-2024-35152 can be exploited by an authenticated user through specially crafted queries.
What impact does CVE-2024-35152 have on systems?
The impact of CVE-2024-35152 is a potential denial of service, which can disrupt the availability of the affected systems.