### [CVE-2024-35136](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35136) ![](https://img.shields.io/static/v1?label=Product&message=Db2%20for%20Linux%2C%20UNIX%20and%20Windows&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=10.5%2C%2011.1%2C%2011.5%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-943%20Improper%20Neutralization%20of%20Special%20Elements%20in%20Data%20Query%20Logic&color=brightgreen) ### Description IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds