CVE-2021-20579: Medium severity ibm db2 universal database vulnerability
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTOREVAL is set to DEFFEREDFORCE. IBM X-Force ID: 199283.
Other sources
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTOREVAL is set to DEFFEREDFORCE.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM DB2 vulnerability?
The vulnerability ID for this IBM DB2 vulnerability is CVE-2021-20579.
What is the severity of CVE-2021-20579?
The severity of CVE-2021-20579 is medium.
Which versions of IBM DB2 are affected by CVE-2021-20579?
IBM DB2 versions 9.7, 10.1, 10.5, 11.1, and 11.5 are affected by CVE-2021-20579.
What is the impact of CVE-2021-20579?
CVE-2021-20579 allows a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE.
Is there any additional information available about CVE-2021-20579?
Yes, you can find additional information about CVE-2021-20579 on the IBM X-Force ID: 199283 page.