PT-2023-2143 · Ibm · Ibm Db2

Published

2023-02-08

·

Updated

2023-06-27

·

CVE-2022-43927

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Db2 for Linux, UNIX and Windows versions 10.5 through 11.5
Description The issue is related to insufficient protection of service data when processing tables, which can allow a remote attacker to gain unauthorized access to protected information. This is due to improper privilege management when a specially crafted table access is used.
Recommendations For IBM Db2 for Linux, UNIX and Windows versions 10.5 through 11.5, update to a version that includes the fix for this issue to prevent information disclosure due to improper privilege management. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2023-01884
CVE-2022-43927

Affected Products

Ibm Db2