QID 20364
QID 20364: IBM Db2 Arbitrary Code Execution Vulnerability (7010747)
IBM Db2 with Federated configuration is vulnerable to arbitrary code execution as Db2 instance owner.
Affected Versions:
IBM DB2 11.5 prior to version V11.5.7
IBM DB2 11.5 prior to version V11.5.8
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS
A local user with SYSADM privileges could overflow the buffer and execute arbitrary code on the system.
Solution
Please refer to the following security advisory7010747 for further information.
Vendor References
- 7010747 -
www.ibm.com/support/pages/node/7010747
CVEs related to QID 20364
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7010747 |
|