CVE-2023-29257: High severity ibm cloud pak for business automation vulnerability
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM X-Force ID: 252011.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29257?
The severity of CVE-2023-29257 is high with a severity value of 7.2.
What is IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5?
IBM Db2 is a database management system for Linux, UNIX, and Windows that includes the Db2 Connect Server.
How does CVE-2023-29257 impact IBM Db2?
CVE-2023-29257 allows a database administrator of one database to execute code or read/write files from another database within the same instance in IBM Db2.
Which versions of IBM Db2 are affected by CVE-2023-29257?
Versions 10.5, 11.1, and 11.5 of IBM Db2 are affected by CVE-2023-29257.
How can I fix CVE-2023-29257?
To fix CVE-2023-29257, it is recommended to apply the necessary patches or updates provided by IBM Db2.