QID 20379

Date Published: 2023-11-21

QID 20379: IBM DB2 Remote Code Execution (RCE) Vulnerability (7047724)

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Affected Versions:
10.5.0.x all versions
11.1 prior to version 11.1.4 FP7
11.5 prior to version 11.5.7
11.5 prior to version 11.5.8
Note: This QID does not checks for the IBM SDK, Java Technology Edition. Hence set as practice

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS

Successful exploitation could allow a remote attacker to execute arbitrary code on the system

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.6 severity.
  • Solution
    Please refer to the following security advisory7047724 for further information.
    Vendor References

    CVEs related to QID 20379

    Software Advisories
    Advisory ID Software Component Link
    7047724 URL Logo www.ibm.com/support/pages/node/7047724