QID 20378

Date Published: 2023-11-21

QID 20378: IBM DB2 Multiple Vulnerabilities (7047556)

There are multiple vulnerabilities in IBM Runtime Environment Java Version 7.1.5.17 and earlier, 8.0.8.4 and earlier used by IBM Db2. These issues were disclosed as part of the IBM Java SDK updates in April 2023.

Affected Versions:
11.1 prior to version 11.1.4 FP7
11.5 prior to version 11.5.7
11.5 prior to version 11.5.8
Note: This QID does not checks for the IBM SDK, Java Technology Edition. Hence set as practice

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation of this vulnerability could compromise confidentiality, integrity and availability

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Please refer to the following security advisory7047556 for further information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    7047556 URL Logo www.ibm.com/support/pages/node/7047556