← Back

CVE-2020-4355

nvd nist
Published: Jul 1, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service, caused by improper handling of Secure Sockets Layer (SSL) renegotiation requests. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to increase the resource usage on the system. IBM X-Force ID: 178507.

Affected (5)

Products: Ibm: Db2
1 product
Db2
Configuration A
5 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 10.1.0.0
Version 10.5.0.0
Version 11.1.0.0
Version 11.5.0.0
Version 9.7.0.0
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (4)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.