CVE-2023-38729

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 3, 2024
Updated: Jun 10, 2024
CWE ID 200

Summary

CVE-2023-38729: IBM Db2 for Linux, UNIX and Windows versions 10.5, 11.1, and 11.5 contain a sensitive information disclosure vulnerability. Using the ADMIN_CMD feature for IMPORT or EXPORT functions can inadvertently reveal confidential data. IBM's X-Force has assigned ID 262259 to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM DB2
  • IBM DB2 Connect

Affected Vendors

  • IBM Corporation