QID 20260
Date Published: 2022-07-07
QID 20260: IBM DB2 Information Disclosure Vulnerability (6597993)
IBM Db2 is vulnerable to an information disclosure caused by improper privilege management when table function is used.
Affected Versions:
IBM DB2 up to V9.7 FP11
IBM DB2 up to V10.1 FP6
IBM DB2 up to V10.5 FP11
IBM DB2 up to V11.1.4 FP 7
IBM DB2 up to 11.5 m7fp0
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS
Note: Patch is not yet available for Release 9.7 Windows OS.
Successful exploitation could lead to leakage of sensitive information
Solution
Please refer to the following links 6597993
Vendor References
- 6597993 -
www.ibm.com/support/pages/node/6597993
CVEs related to QID 20260
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6597993 |
|