IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7145721 | vendor advisory |
https://https://exchange.xforce.ibmcloud.com/vulnerabilities/262259 | broken link third party advisory |
https://security.netapp.com/advisory/ntap-20240517-0004/ | third party advisory |