CVE-2023-38720
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 16, 2023
Updated: Dec 22, 2023
CWE ID 20
Summary
CVE-2023-38720 is a newly disclosed vulnerability affecting IBM Db2 for Linux, UNIX, and Windows versions 11.5 and 11.5. This issue enables an attacker to execute a denial-of-service (DoS) attack using a specially crafted ALTER TABLE statement. The vulnerability, tracked as IBM X-Force ID: 261616, allows an attacker to cause the database server to become unresponsive, causing potential disruptions to services relying on the affected database. Organizations using these Db2 versions are advised to apply the available patch or update to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- IBM DB2
Affected Vendors
- IBM Corporation