QID 20339

QID 20339: IBM DB2 Multiple Vulnerabilities (1073908)

There are multiple vulnerabilities in IBM Runtime Environment Java Version 7.0.10.45 and earlier, 7.1.4.45 and earlier, 8.0.5.37 and earlier used by IBM Db2. These issues were disclosed as part of the IBM Java SDK updates in July 2019.

QID Detection Logic: Authenticated (DB2): This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS

Could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and no availability impact.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Please refer to the following links 1073908
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    1073908 URL Logo www.ibm.com/support/pages/node/1073908