Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a vulnerability that can cause a denial of service when a specially crafted query targets range‑partitioned tables. The flaw is identified as an out‑of‑memory condition (CWE‑770) that can lead the database to become unresponsive or crash, thereby interrupting availability for the affected databases and any dependent applications.
Affected Systems
The affected systems are IBM Db2 products running any level of the 11.5 or 12.1 releases, specifically up to and including 11.5.9 and 12.1.4. Any database instance that uses range partitioned tables and is running one of these releases is at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity impact, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker who can submit queries to the database—such as a privileged user or a remote client with query permissions—could trigger the denial of service. The exploit would rely on executing a specially crafted query against a range‑partitioned table, causing an out‑of‑memory error and service disruption.
OpenCVE Enrichment