QID 20336
Date Published: 2023-05-10
QID 20336: IBM DB2 Information Disclosure Vulnerability (1116819)
Db2 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users, after running LOAD or UPDATE ALERT CFG through the ADMIN_CMD() stored procedure.
Affected Versions:
All fix pack levels of IBM Db2 V9.7, V10.1, V10.5, V11.1, and V11.5 editions on all platforms are affected.
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS
Db2 is vulnerable to an information disclosure vulnerability.
Solution
Please refer to the following links 1116819
Vendor References
- 1116819 -
www.ibm.com/support/pages/node/1116819
CVEs related to QID 20336
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 1116819 |
|