PT-2024-13028 · Ibm · Db2

Published

2024-05-29

·

Updated

2025-08-18

·

CVE-2023-42005

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 3.5 through 4.8
Description The issue allows a user with access to the Kubernetes pod to make system calls, compromising the security of containers.
Recommendations For versions 3.5 through 4.8, consider restricting access to the Kubernetes pod to minimize the risk of exploitation. As a temporary workaround, review and limit system calls made from within the pod until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-42005

Affected Products

Db2