QID 20320

Date Published: 2023-02-06

QID 20320: IBM DB2 Multiple Vulnerabilities (6847293)

Multiple vulnerabilities in the Expat library affect IBM Db2 Net Search Extender may lead to denial of service or arbitrary code execution.

Affected Versions:
prior to special build 41220 for DB2 9.7 Fix Pack 11
prior to special build 41219 for DB2 10.1 Fix Pack 6
prior to special build 41221 for DB2 10.5 Fix Pack 11
prior to special build 41222 for DB2 11.1.4 Fix Pack 7
QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation may lead to denial of service or arbitrary code execution.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Please refer to the following links 6847293
    Vendor References

    CVEs related to QID 20320

    Software Advisories
    Advisory ID Software Component Link
    6847293 URL Logo www.ibm.com/support/pages/node/6847293