QID 20248
Date Published: 2022-07-11
QID 20248: IBM DB2 Information Disclosure Vulnerability (6523810)
DB2 is a family of data management products, including database servers, developed by IBM.
BM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from.
Affected Versions:
IBM DB2 Prior to V11.1 FP6
IBM DB2 Prior to V11.5 M7FP0
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows):
This QID checks for vulnerable version of DB2 on windows OS
Successful exploitation could lead to information disclosure
Solution
Please refer to the following links 6523810
Vendor References
- 6523810 -
www.ibm.com/support/pages/node/6523810
CVEs related to QID 20248
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6523810 |
|