VYPR
Unrated severityNVD Advisory· Published Jan 22, 2024· Updated Feb 13, 2025

IBM Db2 denial of service

CVE-2023-47746

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 272644.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Db2 on Linux, UNIX, and Windows allows authenticated users to cause denial of service via a specially crafted query.

Vulnerability

IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 10.5.0.x, 11.1.4.x, and 11.5.x are vulnerable to a denial of service condition. An authenticated user with CONNECT privileges can exploit this vulnerability by executing a specially crafted query. Earlier releases such as 10.1 and 9.7 may also be affected but are no longer supported [1].

Exploitation

To exploit this vulnerability, an attacker needs valid credentials with at least CONNECT privileges on the Db2 instance. The attacker then submits a specially crafted query to the database server. The CVSS vector indicates the attack complexity is high (AC:H), meaning special conditions must be met for the attack to succeed, and no user interaction is required [1].

Impact

Successful exploitation results in a denial of service condition, causing the Db2 server to become unresponsive or crash. This impacts availability (A:H) but does not affect confidentiality or integrity (C:N/I:N) [1]. The attacker does not gain any additional privileges beyond their authenticated session.

Mitigation

IBM has released special builds containing interim fixes for affected versions: V10.5 FP11, V11.1.4 FP7, and V11.5.9. These builds can be downloaded from IBM Fix Central and applied to any affected fixpack level of the respective release. The APAR ID is DT246499. No workaround is documented other than applying the fix [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.