First published: Fri Feb 17 2023(Updated: )
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 | =10.5 | |
Ibm Db2 | =10.5 | |
Ibm Db2 | =10.5 | |
Ibm Db2 | =11.1 | |
Ibm Db2 | =11.1 | |
Ibm Db2 | =11.1 | |
Ibm Db2 | =11.5 | |
Ibm Db2 | =11.5 | |
Ibm Db2 | =11.5 | |
HP HP-UX | ||
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43927 is a vulnerability in IBM Db2 that allows information disclosure due to improper privilege management.
The severity of CVE-2022-43927 is high with a CVSS score of 7.5.
IBM Db2 versions 10.5, 11.1, and 11.5 are affected by CVE-2022-43927.
CVE-2022-43927 occurs when a specially crafted table access is used in IBM Db2 for Linux, UNIX, and Windows.
No, IBM Db2 is not vulnerable on HP-UX, IBM AIX, Linux kernel, Microsoft Windows, or Oracle Solaris.
You can find more information about CVE-2022-43927 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/241671) and the IBM support page (https://www.ibm.com/support/pages/node/6953759).
The Common Weakness Enumerations (CWE) associated with CVE-2022-43927 are CWE-269 and CWE-200.