IBM Db2 denial of service
Description
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 269367.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Db2 federated server versions 11.5.6 through 11.5.8 are vulnerable to denial of service via a specially crafted cursor.
Vulnerability
IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 11.5.6 through 11.5.8 contain a denial-of-service vulnerability in the federated server component [1]. A specially crafted cursor can trigger the issue, but the vendor has not disclosed further technical details to prevent exploitation [1]. All platforms are affected [1].
Exploitation
An attacker with network access can exploit this vulnerability without authentication, but the attack complexity is high according to the CVSS vector (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) [1]. A specially crafted cursor must be sent to the federated server to trigger the denial-of-service condition [1]. The vendor has deliberately withheld the specific replication steps [1].
Impact
Successful exploitation leads to a denial of service, causing the affected Db2 federated server to become unavailable [1]. No impact on confidentiality or integrity is reported [1].
Mitigation
IBM has released interim fixes (special builds) for this vulnerability on the most recent fixpack levels: V10.5 FP11, V11.1.4 FP7, and V11.5.9 [1]. Customers running any affected fixpack level within 11.5.6 through 11.5.8 should obtain the special build from Fix Central and apply it to their appropriate release [1]. No workarounds are available [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: = 11.5
- Range: 11.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/pages/node/7087203mitrevendor-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/269367mitrevdb-entry
- security.netapp.com/advisory/ntap-20240112-0003/mitre
News mentions
0No linked articles in our index yet.