SB2021120915 - Multiple vulnerabilities in IBM DB2
Published: December 9, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-20373)
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to application does not properly impose security restrictions when using the LOAD utility. A remote user can read files in arbitrary directory on the system.
2) Information disclosure (CVE-ID: CVE-2021-29752)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to exposure of remote storage credentials to privileged users. A remote authenticated user can gain access to sensitive information.
3) Incorrect default permissions (CVE-ID: CVE-2020-4976)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A local user with access to the system can view contents of files and directories or modify them.
4) Improper Authorization (CVE-ID: CVE-2021-38931)
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated user can read data from tables their are not authorized to5) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-38926)
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote database user can modify columns of existing tasks and escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-may-be-vulnerable-to-an-information-disclosure-when-using-the-load-utility-as-under-certain-circumstances-the-load-utility-does-not-enforce-directory-restricti/
- https://www.ibm.com/support/pages/node/6523804
- https://www.ibm.com/support/pages/node/6489489
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-is-vulnerable-to-an-information-disclosure-exposing-remote-storage-credentials-to-privileged-users-under-specific-conditions-cve-2021-29752-4/
- https://www.ibm.com/support/pages/node/6489495
- https://www.ibm.com/support/pages/node/6427859
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-could-allow-a-local-user-to-read-and-write-specific-files-due-to-weak-file-permissions-cve-2020-4976-6/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-is-vulnerable-to-an-information-disclosure-as-a-result-of-a-connected-user-having-indirect-read-access-to-a-table-where-they-are-not-authorized-to-select-from/
- https://www.ibm.com/support/pages/node/6523810
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-could-allow-a-local-user-elevated-privileges-due-to-allowing-modification-of-columns-of-existing-tasks-cve-2021-38926/
- https://www.ibm.com/support/pages/node/6523808