IBM CVE -2024-37071), which affects the Db2 database management software on Linux and UNIX systems.

In specific cases, an authenticated user could exploit this vulnerability to conduct a denial of service (DoS) attackby exploiting a memory management error through specially crafted queries.
Read more: IBM Security: Vulnerability allows execution of arbitrary commands
Vulnerability Details
CVE-2024-37071 concerns a memory allocation error in Db2 for Linux, UNIX , and Windows, including Db2 Connect Server. An authorized user could cause a denial of service (DoS) attack by submitting malicious queries. With a CVSS score of 5.3, the vulnerability is rated as moderate and is categorized as CWE-789 (Memory Allocation with Excessive Size Value).
Affected Versions
The vulnerability affects the following versions of IBM Db2 Server:
See also: AI tool lets you discover Zero-Day vulnerabilities
- 10.5.0 to 10.5.11
- 11.1.4 to 11.1.4.7
- 11.5.0 to 11.5.9
Versions running on Windows are not affected.
IBM has already released fixes for the affected versions, which you can download from IBM Fix Central:
- Version 10.5: Corrective release for Fix Pack 11
- Version 11.1: Corrective release for Fix Pack 7
- Version 11.5: Special fixes available

Read also: Microsoft introduces new security features in Windows
Protection measures
- Check if your system is vulnerable.
- Download the fix updates from IBM Fix Central.
- Install updates to ensure the security of your environment.
- Subscribe to IBM security alerts for future updates
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
