IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
2021-12-09T17:15:07.507
2024-11-21T05:46:29.097
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 11.1 | Yes |
Application | ibm | db2 | 11.5 | Yes |
Operating System | hp | hp-ux | - | No |
Operating System | ibm | aix | - | No |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |
Operating System | oracle | solaris | - | No |