IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7277423 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-06-30 20:17
Updated : 2026-07-02 18:36
NVD link : CVE-2026-11906
Mitre link : CVE-2026-11906
CVE.ORG link : CVE-2026-11906
JSON object : View
Products Affected
linux
- linux_kernel
microsoft
- windows
opengroup
- unix
ibm
- db2
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
