CVE-2018-1428: Medium severity ibm db2 universal database vulnerability
Published Mar 22, 2018
·Updated
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.
Affected Software
6 affected components
IBM DB2=9.7
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=11.1
Linux Linux kernel
Microsoft Windows
Event History
Mar 22, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1428?
The severity of CVE-2018-1428 is rated as medium with a score of 5.5.
2
How do I fix CVE-2018-1428?
To fix CVE-2018-1428, ensure you upgrade to the latest version of IBM DB2 that addresses the use of weaker cryptographic algorithms.
3
What versions of IBM DB2 are affected by CVE-2018-1428?
CVE-2018-1428 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1.
4
What type of vulnerability is CVE-2018-1428?
CVE-2018-1428 is classified under cryptographic weaknesses, specifically the use of weaker than expected cryptographic algorithms.
5
Can CVE-2018-1428 lead to data breaches?
Yes, CVE-2018-1428 could allow an attacker to decrypt highly sensitive information, potentially leading to data breaches.