QID 20371

Date Published: 2023-11-20

QID 20371: IBM DB2 Buffer Overflow and Arbitary Code Execution Vulnerability (7047565)

A vulnerability in libqb affects IBM Db2 High-Availability deployments using Pacemaker. Affected Versions:
IBM DB2 11.5 prior to version V11.5.7 for Linux
IBM DB2 11.5 prior to version V11.5.8 for Linux

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

By sending a specially crafted request, a remote attacker could overflow a buffer and execute arbitrary code on the system

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution
    Please refer to the following security advisory7047565 for further information.
    Vendor References

    CVEs related to QID 20371

    Software Advisories
    Advisory ID Software Component Link
    7047565 URL Logo www.ibm.com/support/pages/node/7047565