CVE-2024-35136

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*

History

21 Sep 2024, 10:15

Type Values Removed Values Added
Summary (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 291307. (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.

23 Aug 2024, 19:08

Type Values Removed Values Added
Summary
  • (es) El servidor federado IBM Db2 para Linux, UNIX y Windows (incluye DB2 Connect Server) 10.5, 11.1 y 11.5 es vulnerable a la denegación de servicio con una consulta especialmente manipulada bajo ciertas condiciones. ID de IBM X-Force: 291307.
First Time Ibm db2
Ibm
CWE NVD-CWE-noinfo
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/291307 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/291307 - Vendor Advisory
References () https://www.ibm.com/support/pages/node/7165341 - () https://www.ibm.com/support/pages/node/7165341 - Vendor Advisory
CPE cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5

14 Aug 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 18:15

Updated : 2024-09-21 10:15


NVD link : CVE-2024-35136

Mitre link : CVE-2024-35136

CVE.ORG link : CVE-2024-35136


JSON object : View

Products Affected

ibm

  • db2
CWE
NVD-CWE-noinfo CWE-943

Improper Neutralization of Special Elements in Data Query Logic