Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 for Linux, Unix and Windows can allow a remote authenticated attacker to trigger uncontrolled resource consumption, leading to a denial of service. The weakness is a lack of resource use control in the database server, identified as CWE-400. An attacker who can log in can cause the database to become unavailable to legitimate users.
Affected Systems
Affected products include IBM Db2 11.5.0 to 11.5.9 and 12.1.0 to 12.1.5, covering Linux, Unix and Windows platforms and the DB2 Connect Server component.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of 0.0049 (less than 1%) shows a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote authentication, so only accounts with valid credentials can trigger the denial of service attack.
OpenCVE Enrichment