Lucene search

K
ibmIBM7036F1DB3AEC373A20A21241E07E5E1B83903F632872606EBDCF06BDAAF95EC2
HistorySep 22, 2022 - 8:47 p.m.

Security Bulletin: Multiple security vulnerabilities may affect IBM DB2 shipped with Predictive Maintenance and Quality and Predictive Maintenance Insights On-Premises (CVE-2021-38931,CVE-2021-20373)

2022-09-2220:47:20
www.ibm.com
18
ibm db2
predictive maintenance
quality
insights
security bulletin
vulnerabilities
fix pack version 11.5.7
cve-2021-38931
cve-2021-20373
cve-2022-22390
cve-2022-22389
expat library

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

47.6%

Summary

IBM DB2 is shipped with IBM Predictive Maintenance and Quality and Predictive Maintenance Insights On-Premises. Information about security vulnerabilities affecting DB2 has been published in multiple security bulletins as below. Interim fix is provided by DB2 for each of the fix pack versions as per the Security Bulletins listed in Remediation section below.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Predictive Maintenance and Quality 1.0.x
IBM Predictive Maintenance and Quality 2.5.x
IBM Predictive Maintenance and Quality 2.0.x

Remediation/Fixes

Please refer to below security bulletins for details on the vulnerabilities. The recommended solution is to apply interim fix as listed in each Security Bulletin below on DB2 Server (Fix Pack version 11.5.7) for IBM Predictive Maintenance and Quality and Predictive Maintenance Insights On-Premises installations.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrational_quality_managerMatch1.0.x
OR
ibmrational_quality_managerMatch2.5.x
OR
ibmrational_quality_managerMatch2.0.x

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

47.6%

Related for 7036F1DB3AEC373A20A21241E07E5E1B83903F632872606EBDCF06BDAAF95EC2