QID 20267

Date Published: 2022-08-22

QID 20267: IBM DB2 Information Disclosure Vulnerability (6523804)

IBM Db2 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. Affected Versions:
Affected Versions:
IBM DB2 up to V9.7 FP11
IBM DB2 up to V10.1 FP6
IBM DB2 up to V10.5 FP11
IBM DB2 up to V11.1.4 FP 6
IBM DB2 up to 11.5 m7fp0
QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation could lead to leakage of sensitive information

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please refer to the following links 6523804
    Vendor References

    CVEs related to QID 20267

    Software Advisories
    Advisory ID Software Component Link
    6523804 URL Logo www.ibm.com/support/pages/node/6523804