First published: Thu Mar 22 2018(Updated: )
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.5 | |
IBM DB2 Universal Database | =11.1 | |
Linux Kernel | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1571 is classified as a moderate severity vulnerability due to its potential impact on sensitive information.
To remediate CVE-2017-1571, upgrade your IBM DB2 software to a version that uses stronger cryptographic algorithms.
CVE-2017-1571 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1.
CVE-2017-1571 can allow attackers to decrypt highly sensitive information, posing a significant data security risk.
There are no official workarounds for CVE-2017-1571; upgrading to a secure version is the recommended solution.