CVE-2021-38931: Medium severity ibm db2 universal database vulnerability
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this information disclosure vulnerability in IBM Db2?
The vulnerability ID is CVE-2021-38931.
What software versions of IBM Db2 are affected by this vulnerability?
IBM Db2 11.1 and 11.5 are affected by this vulnerability.
What is the severity level of CVE-2021-38931?
The severity level of CVE-2021-38931 is medium (6.5).
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by gaining indirect read access to a table where they are not authorized to select from.
Are there any references available for this vulnerability?
Yes, you can find more information about this vulnerability at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/210418), [link2](https://security.netapp.com/advisory/ntap-20220114-0001/), and [link3](https://www.ibm.com/support/pages/node/6523810).