QID 20259

Date Published: 2022-07-07

QID 20259: IBM DB2 Multiple Vulnerabilities (6597637)

DB2 is a family of data management products, including database servers, developed by IBM.

IBM Db2 is affected by multiple vulnerabilities due to the consumed Expat library leading to a denial of service or arbitrary code execution.

Affected Versions:
IBM DB2 up to V9.7 FP11
IBM DB2 up to V10.1 FP6
IBM DB2 up to to V10.5 FP11
IBM DB2 up to to V11.1.4 FP 7
QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable version of DB2 on windows OS

Note: Patch is not yet available for Release 9.7 Windows OS.

Successful exploitation could lead to denial of service or arbitrary code execution

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Please refer to the following links 6597637

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    6597637 URL Logo www.ibm.com/support/pages/node/6597637