7.5

CVE-2022-43927

IBM Db2 for Linux, UNIX and Windows information disclosure

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used.  IBM X-Force ID:  241671.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 10.5 SwPlatform linux
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 10.5 SwPlatform unix
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 10.5 SwPlatform windows
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 11.1 SwPlatform linux
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 11.1 SwPlatform unix
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 11.1 SwPlatform windows
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 11.5 SwPlatform linux
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 11.5 SwPlatform unix
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Ibm ≫ Db2 Version 11.5 SwPlatform windows
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
   Oracle ≫ Solaris Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.459
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
IBM 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://exchange.xforce.ibmcloud.com/vulnerabilities/241671
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/6953759
Patch
Vendor Advisory