IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted XML query.Referenceshttp://www-01.ibm.com/support/docview.wss?uid=swg21692358http://www-01.ibm.com/support/docview.wss?uid=swg1IT05933http://www-01.ibm.com/support/docview.wss?uid=swg1IT05938http://www-01.ibm.com/support/docview.wss?uid=swg1IT05936http://www.securityfocus.com/bid/71734http://www-01.ibm.com/support/docview.wss?uid=swg1IT05937http://www-01.ibm.com/support/docview.wss?uid=swg1IT05939https://exchange.xforce.ibmcloud.com/vulnerabilities/99110