QID 20390

Date Published: 2023-12-27

QID 20390: IBM DB2 Multiple Vulnerabilities (7087225)

IBM Db2 is affected by multiple vulnerabilities in the consumed PCRE library. Affected Versions:
V10.5 prior to version V10.5 FP11
V11.1 prior to version V11.1.4 FP7
V11.5 Prior to version V11.5.8
Note: This QID does not checks for the AIX OS build available for version V11.5.0

QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.

Successful exploitation could compromise Confidentiality, Integrity and Availability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Please refer to the following security advisory7087225 for further information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    7087225 URL Logo www.ibm.com/support/pages/node/7087225