CVE-2022-35637

EUVD-2022-38518
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
ibmCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/C:N/A:H/I:N/AV:N/UI:N/S:U/PR:L/AC:L/RL:O/RC:C/E:U
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
ibmdb2
10.5
ibmdb2
10.5
ibmdb2
10.5
ibmdb2
11.1
ibmdb2
11.1
ibmdb2
11.1
ibmdb2
11.5
ibmdb2
11.5
ibmdb2
11.5
𝑥
= Vulnerable software versions