CVE-2023-47152: IBM Db2 information disclosure
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47152?
CVE-2023-47152 is classified as a high severity vulnerability due to its impact on cryptographic algorithms and potential information disclosure.
How do I fix CVE-2023-47152?
To mitigate CVE-2023-47152, update IBM Db2 for Linux, UNIX, and Windows to the latest version that is not susceptible to this vulnerability.
What does CVE-2023-47152 affect?
CVE-2023-47152 affects IBM Db2 for Linux, UNIX, and Windows versions up to and including 11.5.9.
What are the potential risks of CVE-2023-47152?
The potential risks of CVE-2023-47152 include exposure of sensitive information through stack traces and compromise of cryptographic integrity.
Is CVE-2023-47152 exploitable remotely?
CVE-2023-47152 may be exploitable remotely under certain conditions, depending on the implementation of the affected database system.