IBM Db2 denial of service
Description
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted XML query statement. IBM X-Force ID: 262258.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Db2 for Linux, UNIX and Windows is vulnerable to denial of service via a specially crafted XML query statement.
Vulnerability
IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 10.5, 11.1, and 11.5 are vulnerable to denial of service when processing a specially crafted XML query statement. The vulnerability exists in the XML query parsing component, which can be exploited without requiring any special configuration beyond default settings.
Exploitation
An attacker with network access to the Db2 database server can send a malicious XML query statement. No authentication is required to trigger the vulnerable code path. The attacker does not need any special privileges or user interaction; sending the crafted query is sufficient to cause the denial of service.
Impact
Successful exploitation leads to a denial of service, making the database instance unavailable until manual intervention. This impacts the availability of the database service, potentially disrupting applications that rely on it.
Mitigation
No specific fix is disclosed in the available references. Affected customers should monitor IBM's security advisories for updates. As a general mitigation, restrict network access to the database server and apply the principle of least privilege to database connections.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 10.5, 11.1, 11.5
- Range: 10.5, 11.1 ,11.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/pages/node/7047489mitrevendor-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/262258mitrevdb-entry
- security.netapp.com/advisory/ntap-20231116-0006/mitre
News mentions
0No linked articles in our index yet.