QID 20372

Date Published: 2023-11-20

QID 20372: IBM DB2 information disclosure Vulnerability (7047481)

IBM Db2 is vulnerable to an information disclosure vulnerability due to the consumed GSKit library.

Affected Versions:
10.5 prior to version 10.5 FP11
11.1 prior to version 11.1.4 FP7
11.5 prior to version 11.5.7
11.5 prior to version 11.5.8
Note: This QID does not checks for the workaround. Hence kept as practice

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS

Attacker could exploit this vulnerability to obtain sensitive information

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Please refer to the following security advisory7047481 for further information.
    Vendor References

    CVEs related to QID 20372

    Software Advisories
    Advisory ID Software Component Link
    7047481 URL Logo www.ibm.com/support/pages/node/7047481