CVE-2023-47158

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
OR cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:29

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/270750 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/270750 - VDB Entry, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240307-0002/ - () https://security.netapp.com/advisory/ntap-20240307-0002/ -
References () https://www.ibm.com/support/pages/node/7105496 - Patch, Vendor Advisory () https://www.ibm.com/support/pages/node/7105496 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3

07 Mar 2024, 17:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240307-0002/ -

05 Feb 2024, 19:15

Type Values Removed Values Added
Summary IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750. IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750.

25 Jan 2024, 02:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7105496 - () https://www.ibm.com/support/pages/node/7105496 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/270750 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/270750 - VDB Entry, Vendor Advisory
First Time Ibm linux On Ibm Z
Oracle solaris
Ibm db2
Ibm aix
Oracle
Microsoft
Hp
Microsoft windows
Linux
Linux linux Kernel
Ibm
Hp hp-ux
CWE CWE-20 NVD-CWE-noinfo

22 Jan 2024, 20:28

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-22 20:15

Updated : 2024-11-21 08:29


NVD link : CVE-2023-47158

Mitre link : CVE-2023-47158

CVE.ORG link : CVE-2023-47158


JSON object : View

Products Affected

ibm

  • aix
  • linux_on_ibm_z
  • db2

oracle

  • solaris

microsoft

  • windows

hp

  • hp-ux

linux

  • linux_kernel
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo