CVE-2024-40679: IBM Db2 information disclosure
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40679?
CVE-2024-40679 has been classified as a moderate severity information disclosure vulnerability.
How do I fix CVE-2024-40679?
To address CVE-2024-40679, upgrade IBM Db2 to a version later than 11.5.9 that does not include this vulnerability.
What versions of IBM Db2 are impacted by CVE-2024-40679?
CVE-2024-40679 affects IBM Db2 versions 11.5.0 to 11.5.9 on Linux, UNIX, and Windows.
What kind of information is disclosed in CVE-2024-40679?
CVE-2024-40679 may lead to sensitive information being exposed in log files under specific conditions.
Is CVE-2024-40679 present in Db2 Connect Server?
Yes, CVE-2024-40679 affects IBM Db2 Connect Server that runs on the specified vulnerable versions.