Lucene search

K
cvelistIbmCVELIST:CVE-2021-29702
HistoryJun 16, 2021 - 4:15 p.m.

CVE-2021-29702

2021-06-1616:15:24
ibm
www.cve.org
10
db2
linux
unix
windows
vulnerability
denial of service
ibm
x-force
select statement
abnormal termination

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.3%

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.

CNA Affected

[
  {
    "product": "DB2 for Linux- UNIX and Windows",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "11.1.4"
      },
      {
        "status": "affected",
        "version": "11.5.5"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.3%

Related for CVELIST:CVE-2021-29702