CVE-2012-0712: IBM DB2
Medium severity, CVSS 4.0. EPSS: 2% chance of exploitation in the next 30 days.
The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
Affected products
- IBM DB2: version 9.5 only; version 9.7 only; version 9.8 only
Published 2012-03-20. Last modified 2026-06-16.