CVE-2023-29257
Published on: Not Yet Published
Last Modified on: 05/11/2023 03:15:00 PM UTC
Certain versions of Db2 from Ibm contain the following vulnerability:
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM X-Force ID: 252011.
- CVE-2023-29257 has been assigned by
p[email protected] to track the vulnerability - currently rated as HIGH severity.
- Weakness Type: 284 Improper Access Control
- Affected Vendor/Software:
IBM - Db2 for Linux, UNIX and Windows version = 10.5, 11.1 ,11.5
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
April 2023 IBM DB2 Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Security Bulletin: IBM® Db2® is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. (CVE-2023-29257) | www.ibm.com text/html |
![]() |
IBM X-Force Exchange | exchange.xforce.ibmcloud.com text/html |
![]() |
Related QID Numbers
- 20347 IBM DB2 Remote Code Execution (RCE) Vulnerability (6985691) (6985677)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Ibm | Db2 | All | All | All | All |
Application | Ibm | Db2 | 10.5 | - | All | All |
Application | Ibm | Db2 | 10.5 | fp1 | All | All |
Application | Ibm | Db2 | 10.5 | fp10 | All | All |
Application | Ibm | Db2 | 10.5 | fp2 | All | All |
Application | Ibm | Db2 | 10.5 | fp3 | All | All |
Application | Ibm | Db2 | 10.5 | fp3a | All | All |
Application | Ibm | Db2 | 10.5 | fp4 | All | All |
Application | Ibm | Db2 | 10.5 | fp5 | All | All |
Application | Ibm | Db2 | 10.5 | fp6 | All | All |
Application | Ibm | Db2 | 10.5 | fp7 | All | All |
Application | Ibm | Db2 | 10.5 | fp8 | All | All |
Application | Ibm | Db2 | 10.5 | fp9 | All | All |
Application | Ibm | Db2 | 11.1.4 | - | All | All |
Application | Ibm | Db2 | 11.1.4 | fp1 | All | All |
Application | Ibm | Db2 | 11.1.4 | fp2 | All | All |
Application | Ibm | Db2 | 11.1.4 | fp3 | All | All |
Application | Ibm | Db2 | 11.1.4 | fp4 | All | All |
Application | Ibm | Db2 | 11.1.4 | fp5 | All | All |
Application | Ibm | Db2 | 11.1.4 | fp6 | All | All |
Operating System | Linux | Linux Kernel | - | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
- cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:-:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp1:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp10:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp2:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp3:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp3a:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp4:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp5:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp6:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp7:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp8:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:10.5:fp9:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:11.1.4:-:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:11.1.4:fp1:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:11.1.4:fp2:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:11.1.4:fp3:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:11.1.4:fp4:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:11.1.4:fp5:*:*:*:*:*:*:
- cpe:2.3:a:ibm:db2:11.1.4:fp6:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-29257 : #IBM Db2 for #Linux, UNIX and #Windows includes Db2 Connect Server 10.5, 11.1, and 11.5 is vulne… twitter.com/i/web/status/1… | 2023-04-26 13:06:26 |
![]() |
CVE-2023-29257 | IBM DB2 10.5/11.1/11.5 Privilege Escalation (XFDB-252011) dlvr.it/Sn66Rs | 2023-04-26 14:08:11 |
![]() |
Potentially Critical CVE Detected! CVE-2023-29257 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server)… twitter.com/i/web/status/1… | 2023-04-26 14:11:01 |