QID 20323

Date Published: 2023-02-20

QID 20323: IBM DB2 Information Disclosure Vulnerability (6618779)

IBM Db2 may be vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used.

Affected Versions:
IBM DB2 up to V9.7 FP11
IBM DB2 up to V10.1 FP6
IBM DB2 up to V10.5 FP11
IBM DB2 up to V11.1 FP 7
IBM DB2 up to 11.5 FP8
QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation could lead to leakage of sensitive information

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please refer to the following links 6618779
    Vendor References

    CVEs related to QID 20323

    Software Advisories
    Advisory ID Software Component Link
    6618779 URL Logo www.ibm.com/support/pages/node/6618779