QID 20379
Date Published: 2023-11-21
QID 20379: IBM DB2 Remote Code Execution (RCE) Vulnerability (7047724)
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Affected Versions:
10.5.0.x all versions
11.1 prior to version 11.1.4 FP7
11.5 prior to version 11.5.7
11.5 prior to version 11.5.8
Note: This QID does not checks for the IBM SDK, Java Technology Edition. Hence set as practice
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS
Successful exploitation could allow a remote attacker to execute arbitrary code on the system
- 7047724 -
www.ibm.com/support/pages/node/7047724
CVEs related to QID 20379
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7047724 |
|