QID 20246

Date Published: 2022-04-05

QID 20246: IBM DB2 Information Disclosure Vulnerability (6466369)

DB2 is a family of data management products, including database servers, developed by IBM.

IBM Db2 is vulnerable to an information disclosure Vulnerability

Affected Versions:
IBM DB2 Prior to V9.7 FP11
IBM DB2 Prior to V10.1 FP6
IBM DB2 Prior to V10.5 FP11
IBM DB2 Prior to V11.1 FP6
IBM DB2 Prior to V11.5 Mod 6 Fix Pack 0

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable version of DB2 on windows OS

Successful exploitation could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Please refer to the following links 6466369

    Vendor References

    CVEs related to QID 20246

    Software Advisories
    Advisory ID Software Component Link
    6466369 URL Logo www.ibm.com/support/pages/node/6466369