IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7277423 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
02 Jul 2026, 18:36
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Linux
Ibm db2 Linux linux Kernel Microsoft windows Opengroup unix Ibm Microsoft Opengroup |
|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:opengroup:unix:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:* |
|
| References | () https://www.ibm.com/support/pages/node/7277423 - Vendor Advisory |
30 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 20:17
Updated : 2026-07-02 18:36
NVD link : CVE-2026-11906
Mitre link : CVE-2026-11906
CVE.ORG link : CVE-2026-11906
JSON object : View
Products Affected
opengroup
- unix
ibm
- db2
microsoft
- windows
linux
- linux_kernel
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
