QID 20245

Date Published: 2022-02-14

QID 20245: IBM DB2 Security Update for Log4j

DB2 is a family of data management products, including database servers, developed by IBM.

Apache Log4j open source library used by IBM Db2 is affected by a vulnerability that could allow a remote attacker to execute arbitrary code on the system.

Affected Versions:
IBM DB2 Prior to V11.5 All versions
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Exploit could allow a remote attacker to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution

    Please refer to the following links cve-2021-44228

    CVEs related to QID 20245

    Software Advisories
    Advisory ID Software Component Link
    security-bulletin-vulnerability-in-apache-log4j URL Logo www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-apache-log4j-affects-some-features-of-ibm-db2-cve-2021-44228-3/