QID 20269

Date Published: 2023-01-03

QID 20269: IBM DB2 Multiple Vulnerabilities (6466365)

Multiple vulnerabilities in dependent libraries affect IBM Db2 leading to denial of service or privilege escalation.

Affected Versions:
IBM DB2 up to V11.1.4 FP 6
IBM DB2 prior to 11.5 m6fp0
QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS

An authenticated attacker could exploit this vulnerability to gain elevated privileges.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to the following links 6466365
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    6466365 URL Logo www.ibm.com/support/pages/node/6466365