IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/6523804 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/195521 | VDB Entry Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220225-0005/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-12-09 09:15
Updated : 2022-03-31 09:30
NVD link : CVE-2021-20373
Mitre link : CVE-2021-20373
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
ibm
- db2
- aix
microsoft
- windows
hp
- hp-ux
linux
- linux_kernel
oracle
- solaris