QID 20267
Date Published: 2022-08-22
QID 20267: IBM DB2 Information Disclosure Vulnerability (6523804)
IBM Db2 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions.
Affected Versions:
Affected Versions:
IBM DB2 up to V9.7 FP11
IBM DB2 up to V10.1 FP6
IBM DB2 up to V10.5 FP11
IBM DB2 up to V11.1.4 FP 6
IBM DB2 up to 11.5 m7fp0
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS
Successful exploitation could lead to leakage of sensitive information
Solution
Please refer to the following links 6523804
Vendor References
- 6523804 -
www.ibm.com/support/pages/node/6523804
CVEs related to QID 20267
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6523804 |
|