IBM Db2 denial of service
Description
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 272646.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Db2 on Linux, UNIX, and Windows versions 10.1, 10.5, 11.1, and 11.5 allow authenticated users to cause a denial of service via a crafted query.
Vulnerability
IBM Db2 for Linux, UNIX, and Windows (including Db2 Connect Server) versions 10.1, 10.5.0.x, 11.1.4.x, and 11.5.x are vulnerable to a denial of service. An authenticated user with only CONNECT privileges can exploit this vulnerability by executing a specially crafted query. The affected product editions include the Server edition on all supported platforms [1].
Exploitation
An attacker must be authenticated to the database instance and hold the CONNECT privilege, which is typically granted by default to database users. No additional privileges are required. The attacker delivers a specially crafted SQL query to the server. The complexity of the attack is high (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H), suggesting that the crafted query may require specific knowledge of the database schema or timing [1].
Impact
Successful exploitation results in a denial of service condition, making the database temporarily unavailable to legitimate users. The impact is limited to availability (A:H); there is no impact on confidentiality or integrity (C:N/I:N). The attack does not require user interaction, but it does require network access to the Db2 server [1].
Mitigation
IBM has released special builds containing interim fixes for affected versions: V10.5 FP11 (Special Build), V11.1.4 FP7 (Special Build), and V11.5.9. These special builds can be downloaded from IBM Fix Central and applied to any affected fixpack level of the respective release. The APAR ID is DT221786. No workaround is documented; the recommended action is to apply the fix. Older releases (10.1, 9.7, etc.) are no longer supported and may also be affected [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 10.1, 10.5, 11.1
- Range: 10.5, 11.1 ,11.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/pages/node/7105502mitrevendor-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/272646mitrevdb-entry
- security.netapp.com/advisory/ntap-20240307-0002/mitre
News mentions
0No linked articles in our index yet.