CVE-2021-20373Resource Exposure in IBM DB2

CWE-668Resource Exposure3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 46.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9
Latest updateDec 10

Description

IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDibm/db25 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fpmw-wfwq-64g9: IBM Db2 92021-12-10
CVEList
CVE-2021-20373: IBM Db2 92021-12-09
CVE-2021-20373 — Resource Exposure in IBM DB2 | cvebase