QID 20231

Date Published: 2022-04-08

QID 20231: IBM DB2 Multiple Vulnerabilities (6489499,6489493,6489489)

DB2 is a family of data management products, including database servers, developed by IBM.

CVE-2021-29825: IBM Db2 could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP.
CVE-2021-29763: IBM Db2 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service.
CVE-2021-29752: IBM Db2 is vulnerable to an information disclosure, exposing remote storage credentials to privileged users under specific conditions.

Affected Versions:
IBM DB2 Prior to V11.1 FP6
IBM DB2 Prior to V11.5 Mod 6 Fix Pack 0

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable version of DB2 on windows OS

Successful exploit could allow to attacker to compromise Confidentiality, Integrity and Availability

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Please refer to the following links 6489499 6489493 6489489 for more details.

    CVEs related to QID 20231

    Software Advisories
    Advisory ID Software Component Link
    6489489 URL Logo www.ibm.com/support/pages/node/6489489
    6489493 URL Logo www.ibm.com/support/pages/node/6489493
    6489499 URL Logo www.ibm.com/support/pages/node/6489499