CVE-2023-47152Information Exposure via Error Message in IBM DB2

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.1%
top 70.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 22

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDibm/db2< 11.5.9

Patches

🔴Vulnerability Details

2
CVEList
IBM Db2 information disclosure2024-01-22
GHSA
GHSA-74mv-jm52-5vhc: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 112024-01-22
CVE-2023-47152 — Information Exposure via Error Message | cvebase