CVE-2021-29678: High severity ibm db2 universal database vulnerability
Published Dec 9, 2021
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.
Affected Software
11 affected components
IBM DB2=9.7
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=11.1
IBM DB2=11.5
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
NetApp OnCommand Insight
Event History
Dec 9, 2021
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via IBM·10:19 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-29678?
The severity of CVE-2021-29678 is high with a severity value of 8.7.
2
Which software versions are affected by CVE-2021-29678?
IBM Db2 for Linux, UNIX and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5 are affected by CVE-2021-29678.
3
What is the vulnerability description of CVE-2021-29678?
CVE-2021-29678 is a vulnerability in IBM Db2 for Linux, UNIX, and Windows that allows a user with DBADM authority to access other databases and read or modify files.
4
Is IBM Db2 for HP-UX affected by CVE-2021-29678?
No, IBM Db2 for HP-UX is not affected by CVE-2021-29678.
5
How can I fix CVE-2021-29678?
To fix CVE-2021-29678, it is recommended to apply the necessary security patches provided by IBM Db2.