Vulnerability Description
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 | 9.7 |
| Ibm | Aix | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
| Netapp | Oncommand Insight | - |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/173806VDB EntryVendor Advisory
- https://security.netapp.com/advisory/ntap-20210108-0001/Third Party Advisory
- https://www.ibm.com/support/pages/node/2876307Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/173806VDB EntryVendor Advisory
- https://security.netapp.com/advisory/ntap-20210108-0001/Third Party Advisory
- https://www.ibm.com/support/pages/node/2876307Vendor Advisory
FAQ
What is CVE-2020-4135?
CVE-2020-4135 is a vulnerability with a CVSS score of 7.5 (HIGH). IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service fro...
How severe is CVE-2020-4135?
CVE-2020-4135 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-4135?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2, Ibm Aix, Linux Linux Kernel, Microsoft Windows, Netapp Oncommand Insight.