First published: Mon Jan 08 2024(Updated: )
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM IBM® Db2® | <=10.5.0.x | |
IBM IBM® Db2® | <=11.1.4.x | |
IBM IBM® Db2® | <=11.5.x | |
All of | ||
Any of | ||
>=10.5.0.0<=10.5.0.11 | ||
>=11.1.0.0<=11.1.4.7 | ||
>=11.5<=11.5.9 | ||
Any of | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.