CVE-2023-29256
published 2023-07-10CVE-2023-29256: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.85%
53.8th percentile
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used. IBM X-Force ID: 252046.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
cisa8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mvmr-rxwm-hjc9: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10
ghsa_unreviewed·2023-07-10
CVE-2023-29256 [MEDIUM] CWE-269 GHSA-mvmr-rxwm-hjc9: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used. IBM X-Force ID: 252046.
CISA
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
cisa·2023-07-07·CVSS 8.8
CVE-2021-29256 [HIGH] CWE-416 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Vulnerability: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Affected: Arm Mali Graphics Processing Unit (GPU)
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Notes: https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2021-29256
Remediation Due Date: 2023-07-28
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://exchange.xforce.ibmcloud.com/vulnerabilities/252046https://security.netapp.com/advisory/ntap-20230731-0007/https://www.ibm.com/support/pages/node/7010573https://exchange.xforce.ibmcloud.com/vulnerabilities/252046https://security.netapp.com/advisory/ntap-20230731-0007/https://www.ibm.com/support/pages/node/7010573
2023-07-10
Published