CVE Vulnerabilities

CVE-2022-22390

Improper Privilege Management

Published: Jun 24, 2022 | Modified: Oct 28, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Db2 Ibm 9.7 (including) 9.7 (including)
Db2 Ibm 10.1 (including) 10.1 (including)
Db2 Ibm 10.5 (including) 10.5 (including)
Db2 Ibm 11.1 (including) 11.1 (including)
Db2 Ibm 11.5 (including) 11.5 (including)

Potential Mitigations

References