IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.
2024-04-03T13:16:00.150
2025-01-31T15:42:01.847
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 11.1 | Yes |
Application | ibm | db2 | 11.1 | Yes |
Application | ibm | db2 | 11.1 | Yes |
Application | ibm | db2 | 11.5 | Yes |
Application | ibm | db2 | 11.5 | Yes |
Application | ibm | db2 | 11.5 | Yes |
Operating System | hp | hp-ux | - | No |
Operating System | ibm | aix | - | No |
Operating System | ibm | linux_on_ibm_z | - | No |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |
Operating System | oracle | solaris | - | No |