CVE-2023-23487: IBM Db2 audit logging
Published Jul 7, 2023
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to insufficient audit logging.
Affected Software
8 affected components
IBM IBM® Db2®<=11.1.4.7
IBM IBM® Db2®<=11.5.x
IBM DB2=11.1
IBM DB2=11.5
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Jul 7, 2023
CVE Published
12:00 AM
Jul 9, 2023
CVE Published
via MITRE·11:54 PM
Data Sourced
via MITRE·11:54 PM
DescriptionSeverityWeakness
Jul 10, 2023
Data Sourced
04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this IBM Db2 vulnerability?
The vulnerability ID is CVE-2023-23487.
2
What type of vulnerability is this?
This vulnerability is categorized as an insufficient audit logging vulnerability.
3
Which versions of IBM Db2 are affected by this vulnerability?
IBM Db2 for Linux, UNIX and Windows versions 11.1.4.7 and 11.5.x are affected.
4
What is the severity of CVE-2023-23487?
The severity of CVE-2023-23487 is medium.
5
How can I fix this vulnerability in IBM Db2?
To fix this vulnerability, it is recommended to follow the guidance provided by IBM in their support pages.