VYPR
Unrated severityNVD Advisory· Published Apr 3, 2024· Updated Feb 13, 2025

IBM Db2 for Linux, UNIX and Windows denial of service

CVE-2024-27254

Description

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Db2 federated server versions 10.5, 11.1, and 11.5 are vulnerable to denial of service via a specially crafted query under certain conditions.

Vulnerability

IBM Db2 for Linux, UNIX and Windows (including DB2 Connect Server) versions 10.5.0.x, 11.1.4.x, and 11.5.x are affected by a denial of service vulnerability in the federated server component. Under certain conditions, a specially crafted query can cause the server to crash or become unresponsive [1]. All platforms are affected.

Exploitation

An attacker with low privileges and network access can exploit this vulnerability by sending a specially crafted query to the Db2 federated server. The attack does not require user interaction but does have high attack complexity, meaning the attacker must successfully craft the query and meet specific server conditions [1].

Impact

Successful exploitation leads to a denial of service, impacting the availability of the Db2 server. The CIA impact is limited to availability (high), with no impact on confidentiality or integrity. The CVSS base score is 5.3 (medium) [1].

Mitigation

IBM has released special builds containing interim fixes for the affected releases, available from Fix Central. These builds are based on the most recent fixpack levels: V10.5 FP11, V11.1.4 FP7, and V11.5.9. Customers can apply these special builds to any affected fixpack level of the appropriate release [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.