Lucene search

K
cveIbmCVE-2023-29257
HistoryApr 26, 2023 - 1:15 p.m.

CVE-2023-29257

2023-04-2613:15:08
ibm
web.nvd.nist.gov
68
ibm
db2
linux
unix
windows
remote code execution
database administrator
vulnerability

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0.003

Percentile

71.5%

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM X-Force ID: 252011.

Affected configurations

Nvd
Vulners
Node
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
AND
ibmdb2Range11.1โ€“11.1.4
OR
ibmdb2Range11.5โ€“11.5.8
OR
ibmdb2Match10.5-
OR
ibmdb2Match10.5fp1
OR
ibmdb2Match10.5fp10
OR
ibmdb2Match10.5fp2
OR
ibmdb2Match10.5fp3
OR
ibmdb2Match10.5fp3a
OR
ibmdb2Match10.5fp4
OR
ibmdb2Match10.5fp5
OR
ibmdb2Match10.5fp6
OR
ibmdb2Match10.5fp7
OR
ibmdb2Match10.5fp8
OR
ibmdb2Match10.5fp9
OR
ibmdb2Match11.1.4-
OR
ibmdb2Match11.1.4fp1
OR
ibmdb2Match11.1.4fp2
OR
ibmdb2Match11.1.4fp3
OR
ibmdb2Match11.1.4fp4
OR
ibmdb2Match11.1.4fp5
OR
ibmdb2Match11.1.4fp6
VendorProductVersionCPE
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
ibmdb2*cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:-:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:fp1:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:fp10:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:fp2:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:fp3:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:fp3a:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:fp4:*:*:*:*:*:*
Rows per page:
1-10 of 221

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Db2 for Linux, UNIX and Windows",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "10.5, 11.1 ,11.5"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0.003

Percentile

71.5%

Related for CVE-2023-29257