Impact
IBM Db2 versions 12.1.0 through 12.1.4 have a vulnerability that causes a denial of service when executing non‑fenced federated queries. The weakness allows an attacker with the ability to run these queries to trigger a crash of the Db2 federated server, resulting in an availability outage. The flaw matches CWE‑400 for input or resource exhaustion.
Affected Systems
The affected product is IBM Db2 for the 12.1 release line, including all sub‑releases from 12.1.0 up to 12.1.4. Any deployment that includes a federated wrapper without fenced mode is susceptible until patched.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation to date. The likely attack vector is any user or application capable of issuing federated queries; through such a query the attacker can trigger a crash and disrupt database service availability. While no remote code execution is involved, the impact on business continuity can be significant.
OpenCVE Enrichment