IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted XML query.
https://exchange.xforce.ibmcloud.com/vulnerabilities/99110
http://www.securityfocus.com/bid/71734
http://www-01.ibm.com/support/docview.wss?uid=swg21692358
http://www-01.ibm.com/support/docview.wss?uid=swg1IT05939
http://www-01.ibm.com/support/docview.wss?uid=swg1IT05938
http://www-01.ibm.com/support/docview.wss?uid=swg1IT05937