CVE-2023-33854: Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.
Other sources
IBM Db2U could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33854?
The severity of CVE-2023-33854 is medium with a score of 5.3.
How do I fix CVE-2023-33854?
To fix CVE-2023-33854, apply the latest security patches and updates provided by IBM for the affected Db2 versions.
Which products are affected by CVE-2023-33854?
CVE-2023-33854 affects IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3.
Can an attacker exploit CVE-2023-33854 remotely?
Yes, an attacker could potentially exploit CVE-2023-33854 remotely by being an authenticated user and using man in the middle techniques.
What type of vulnerability is CVE-2023-33854?
CVE-2023-33854 is a vulnerability that allows an authenticated user to bypass client-side validation and manipulate input data.