CVE-2023-47158

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
OR cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

History

07 Mar 2024, 17:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240307-0002/ -

05 Feb 2024, 19:15

Type Values Removed Values Added
Summary IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750. IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750.

25 Jan 2024, 02:02

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7105496 - () https://www.ibm.com/support/pages/node/7105496 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/270750 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/270750 - VDB Entry, Vendor Advisory
CWE CWE-20 NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*
First Time Oracle
Ibm
Linux
Microsoft
Microsoft windows
Ibm db2
Linux linux Kernel
Ibm linux On Ibm Z
Oracle solaris
Hp
Ibm aix
Hp hp-ux

22 Jan 2024, 20:28

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-22 20:15

Updated : 2024-03-07 17:15


NVD link : CVE-2023-47158

Mitre link : CVE-2023-47158

CVE.ORG link : CVE-2023-47158


JSON object : View

Products Affected

linux

  • linux_kernel

oracle

  • solaris

ibm

  • db2
  • aix
  • linux_on_ibm_z

hp

  • hp-ux

microsoft

  • windows
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation