CVE-2024-35136

I

BM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*

History

04 Nov 2025, 17:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240912-0003/ -
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3

21 Sep 2024, 10:15

Type Values Removed Values Added
Summary (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 291307. (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.

23 Aug 2024, 19:08

Type Values Removed Values Added
First Time Ibm db2
Ibm
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:ibm:db2:*:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:windows:*:*
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/291307 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/291307 - Vendor Advisory
References () https://www.ibm.com/support/pages/node/7165341 - () https://www.ibm.com/support/pages/node/7165341 - Vendor Advisory
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5

15 Aug 2024, 13:01

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 18:15

Updated : 2025-11-04 17:15


NVD link : CVE-2024-35136

Mitre link : CVE-2024-35136

CVE.ORG link : CVE-2024-35136


JSON object : View

Products Affected
CWE
CWE-943

Improper Neutralization of Special Elements in Data Query Logic

NVD-CWE-noinfo