QID 20387
Date Published: 2023-12-27
QID 20387: IBM DB2 Privilege Escalation Vulnerability (7078681)
IBM DB2 could allow a user with DATAACCESS privileges to execute routines that they should not have access to.
Affected Versions:
V10.5 prior to V10.5 FP11
V11.1 prior to V11.1.4 FP7
V11.5 prior to V11.5.8
Note: This QID does not checks for the AIX OS build available for version V11.5.0
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows):
This QID checks for vulnerable versions of DB2 on windows OS
Successful exploitation could allow a user with DATAACCESS privileges to execute routines that they should not have access to.
Solution
Please refer to the following security advisory7078681 for further information.
Vendor References
- 7078681 -
www.ibm.com/support/pages/node/7078681
CVEs related to QID 20387
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7078681 |
|