VYPR
Unrated severityNVD Advisory· Published Dec 4, 2023· Updated Feb 13, 2025

IBM Db2 denial of service

CVE-2023-46167

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 269367.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Db2 federated server versions 11.5.6 through 11.5.8 are vulnerable to denial of service via a specially crafted cursor.

Vulnerability

IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 11.5.6 through 11.5.8 contain a denial-of-service vulnerability in the federated server component [1]. A specially crafted cursor can trigger the issue, but the vendor has not disclosed further technical details to prevent exploitation [1]. All platforms are affected [1].

Exploitation

An attacker with network access can exploit this vulnerability without authentication, but the attack complexity is high according to the CVSS vector (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) [1]. A specially crafted cursor must be sent to the federated server to trigger the denial-of-service condition [1]. The vendor has deliberately withheld the specific replication steps [1].

Impact

Successful exploitation leads to a denial of service, causing the affected Db2 federated server to become unavailable [1]. No impact on confidentiality or integrity is reported [1].

Mitigation

IBM has released interim fixes (special builds) for this vulnerability on the most recent fixpack levels: V10.5 FP11, V11.1.4 FP7, and V11.5.9 [1]. Customers running any affected fixpack level within 11.5.6 through 11.5.8 should obtain the special build from Fix Central and apply it to their appropriate release [1]. No workarounds are available [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.