IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM X-Force ID: 252011.
2023-04-26T13:15:08.853
2024-11-21T07:56:45.847
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | db2 | < 11.1.4 | Yes |
Application | ibm | db2 | < 11.5.8 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 11.1.4 | Yes |
Application | ibm | db2 | 11.1.4 | Yes |
Application | ibm | db2 | 11.1.4 | Yes |
Application | ibm | db2 | 11.1.4 | Yes |
Application | ibm | db2 | 11.1.4 | Yes |
Application | ibm | db2 | 11.1.4 | Yes |
Application | ibm | db2 | 11.1.4 | Yes |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |