VYPR
Unrated severityNVD Advisory· Published Dec 4, 2023· Updated Feb 13, 2025

IBM Db2 denial of service

CVE-2023-40687

Description

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted RUNSTATS command on an 8TB table. IBM X-Force ID: 264809.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM DB2 on Linux, UNIX, and Windows is vulnerable to denial of service via a specially crafted RUNSTATS command on an 8TB table.

Vulnerability

IBM DB2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 10.5 FP11, 11.1.4 FP7, and 11.5.x are vulnerable to denial of service. The vulnerability is triggered by a specially crafted RUNSTATS command on a table that is 8TB or larger. Earlier unsupported releases may also be affected [1].

Exploitation

An attacker with low-privilege authenticated access to the database can issue a specially crafted RUNSTATS command against an 8TB table. No user interaction beyond database access is required. The CVSS vector indicates the attack is network-based but with high complexity (AV:N/AC:H/PR:L/UI:N) [1].

Impact

Successful exploitation causes a denial of service, impacting system availability. The CVSS score of 5.3 (medium) reflects no confidentiality or integrity impact, only availability [1].

Mitigation

IBM has released special builds with the interim fix for affected releases (V10.5 FP11, V11.1.4 FP7, V11.5.9) available from Fix Central. Customers on any affected fixpack level can apply the corresponding special build. Earlier unsupported releases should be upgraded [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.