First published: Wed Sep 15 2021(Updated: )
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM IBM® Db2® | =11.1 | |
IBM IBM® Db2® | =11.5 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Opengroup Unix | ||
Oracle Solaris |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-29825.
The severity of CVE-2021-29825 is high with a CVSS score of 7.5.
IBM Db2 for Linux, UNIX, and Windows (including Db2 Connect Server) versions 11.1 and 11.5 are affected.
CVE-2021-29825 can be exploited by using ADMIN_CMD with LOAD or BACKUP in IBM Db2 for Linux, UNIX, and Windows.
Yes, you can find references for CVE-2021-29825 at the following links: [reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/204470), [reference 2](https://security.netapp.com/advisory/ntap-20211029-0005/), [reference 3](https://www.ibm.com/support/pages/node/6489499).