CVE-2021-39002: High severity ibm db2 universal database vulnerability
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39002?
CVE-2021-39002 is a vulnerability in IBM DB2 for Linux, UNIX, and Windows that uses weaker than expected cryptographic algorithms, allowing an attacker to decrypt highly sensitive information.
What versions of IBM DB2 are affected by CVE-2021-39002?
IBM DB2 versions 9.7, 10.1, 10.5, 11.1, and 11.5 are affected by CVE-2021-39002.
What is the severity of CVE-2021-39002?
CVE-2021-39002 has a severity score of 7.5 (High).
How can an attacker exploit CVE-2021-39002?
An attacker can exploit CVE-2021-39002 by using weaker cryptographic algorithms to decrypt highly sensitive information.
Is there a fix available for CVE-2021-39002?
Yes, IBM has provided a fix for CVE-2021-39002. It is recommended to update to the latest version of IBM DB2 that includes the fix.