{"id":2094,"date":"2025-04-28T22:33:35","date_gmt":"2025-04-28T22:33:35","guid":{"rendered":"http:\/\/localhost\/?p=2094"},"modified":"2025-04-28T22:33:35","modified_gmt":"2025-04-28T22:33:35","slug":"security-bulletin-multiple-security-vulnerabilities-have-been-identified-in-ibm-db2-shipped-with-ibm","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=2094","title":{"rendered":"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics"},"content":{"rendered":"<div class=\"vulnerability-details\">\n<h2>Vulnerability Details<\/h2>\n<div class=\"info-section\">\n<h3>Basic Information<\/h3>\n<table class=\"info-table\">\n<tr>\n<th>Title<\/th>\n<td>Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics<\/td>\n<\/tr>\n<tr>\n<th>Type<\/th>\n<td>ibm<\/td>\n<\/tr>\n<tr>\n<th>Published<\/th>\n<td>2025-04-28T20:41:23<\/td>\n<\/tr>\n<tr>\n<th>Last Seen<\/th>\n<td>2025-04-29T02:56:35<\/td>\n<\/tr>\n<tr>\n<th>CVSS Score<\/th>\n<td style=\"color: #cc0000; font-weight: bold;\">9.8 (CRITICAL)<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cvss-section\">\n<h3>CVSS v3 Details<\/h3>\n<table class=\"cvss-table\">\n<tr>\n<th>Attack Vector<\/th>\n<td>NETWORK<\/td>\n<\/tr>\n<tr>\n<th>Attack Complexity<\/th>\n<td>LOW<\/td>\n<\/tr>\n<tr>\n<th>Privileges Required<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>User Interaction<\/th>\n<td>NONE<\/td>\n<\/tr>\n<tr>\n<th>Scope<\/th>\n<td>UNCHANGED<\/td>\n<\/tr>\n<tr>\n<th>Confidentiality Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Integrity Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<tr>\n<th>Availability Impact<\/th>\n<td>HIGH<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"cve-section\">\n<h3>CVE Information<\/h3>\n<table class=\"cve-table\">\n<tr>\n<th>CVE IDs<\/th>\n<td>CVE-2009-0001, CVE-2014-0114, CVE-2014-0193, CVE-2014-3488, CVE-2015-2156, CVE-2016-2402, CVE-2017-12972, CVE-2017-12973, CVE-2017-12974, CVE-2017-18640, CVE-2017-3734, CVE-2017-5637, CVE-2018-10237, CVE-2018-11771, CVE-2018-8009, CVE-2018-8012, CVE-2019-0201, CVE-2019-10086, CVE-2019-10172, CVE-2019-10202, CVE-2019-12402, CVE-2019-16869, CVE-2019-17195, CVE-2019-17571, CVE-2019-9512, CVE-2019-9514, CVE-2019-9515, CVE-2019-9518<\/td>\n<\/tr>\n<tr>\n<th>CWE<\/th>\n<td><\/td>\n<\/tr>\n<tr>\n<th>Bulletin Family<\/th>\n<td>software<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"description-section\">\n<h3>Description<\/h3>\n<div class=\"description-content\">\n            ## Summary<\/p>\n<p>IBM\u00ae DB2\u00ae is shipped as a component of IBM PureData System for Operational Analytics. Information about security vulnerabilities affecting IBM DB2 have been published in a security bulletin.<\/p>\n<p>## Vulnerability Details<\/p>\n<p>**CVEID:**CVE-2017-12973<br \/>\n**DESCRIPTION:** Connect2id Nimbus JOSE+JWT could provide weaker than expected security, caused by proceeding improperly after detection of an invalid HMAC in authenticated AES-CBC decryption. A remote attacker could exploit this vulnerability to conduct a padding oracle attack.<br \/>\nCVSS Base score: 5.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/130789 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2017-12972<br \/>\n**DESCRIPTION:** Connect2id Nimbus JOSE+JWT could provide weaker than expected security, caused by the lack of integer-overflow check when converting length values from bytes to bits. A remote attacker could exploit this vulnerability to conduct a HMAC bypass attack.<br \/>\nCVSS Base score: 5.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/130790 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2018-8012<br \/>\n**DESCRIPTION:** Apache Zookeeper could allow a remote attacker to bypass security restrictions, caused by the failure to enforce authentication or authorization when a server attempts to join a quorum. An attacker could exploit this vulnerability to join the cluster and begin propagating counterfeit changes to the leader.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/143565 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N)  <\/p>\n<p>**CVEID:**CVE-2017-5637<br \/>\n**DESCRIPTION:** Apache Zookeeper is vulnerable to a denial of service, caused by the improper handling of the wchp command. By sending a specially-crafted wchp command, a remote attacker could exploit this vulnerability to cause the application to crash.<br \/>\nCVSS Base score: 5.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/121602 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L)  <\/p>\n<p>**CVEID:**CVE-2018-11771<br \/>\n**DESCRIPTION:** Apache Commons Compress is vulnerable to a denial of service, caused by the failure to return the correct EOF indication after the end of the stream has been reached by the ZipArchiveInputStream method. By reading a specially crafted ZIP archive, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.<br \/>\nCVSS Base score: 3.1<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/148429 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:N\/I:N\/A:L)  <\/p>\n<p>**CVEID:**CVE-2018-10237<br \/>\n**DESCRIPTION:** Google Guava is vulnerable to a denial of service, caused by improper eager allocation checks in the AtomicDoubleArray and CompoundOrdering class. By sending a specially-crafted data, a remote attacker could exploit this vulnerability to cause a denial of service condition.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/142508 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2018-8009<br \/>\n**DESCRIPTION:** Apache Hadoop could could allow a remote attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing &#8220;dot dot slash&#8221; sequences (..\/), an attacker could exploit this vulnerability to write to arbitrary files on the system. Note: This vulnerability is known as &#8220;Zip-Slip&#8221;<br \/>\nCVSS Base score: 5.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/150617 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:H\/A:N)  <\/p>\n<p>**CVEID:**CVE-2016-2402<br \/>\n**DESCRIPTION:** OkHttp is vulnerable to a man-in-the-middle attack. By sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate, a remote attacker could exploit this vulnerability to bypass certificate pinning.<br \/>\nCVSS Base score: 4.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/125848 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2009-0001<br \/>\n**DESCRIPTION:** Apple QuickTime is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when processing RTSP URLs. By persuading a victim to open a specially-crafted RTSP URL, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.<br \/>\nCVSS Base score: 6.8<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/48154 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:M\/Au:N\/C:P\/I:P\/A:P)  <\/p>\n<p>**CVEID:**CVE-2019-9512<br \/>\n**DESCRIPTION:** Multiple vendors are vulnerable to a denial of service, caused by a Ping Flood attack. By sending continual pings to an HTTP\/2 peer, a remote attacker could consume excessive CPU resources.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/164903 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2019-9514<br \/>\n**DESCRIPTION:** Multiple vendors are vulnerable to a denial of service, caused by a Reset Flood attack. By opening a number of streams and sending an invalid request over each stream, a remote attacker could consume excessive CPU resources.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/164640 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2019-9515<br \/>\n**DESCRIPTION:** Multiple vendors are vulnerable to a denial of service, caused by a Settings Flood attack. By sending a stream of SETTINGS frames to the peer, a remote attacker could consume excessive CPU resources.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/165181 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2019-9518<br \/>\n**DESCRIPTION:** Multiple vendors are vulnerable to a denial of service, caused by a Empty Frame Flooding attack. By sending a stream of frames with an empty payload and without the end-of-stream flag, a remote attacker could consume excessive CPU resources.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/164904 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H)  <\/p>\n<p>**CVEID:**CVE-2014-0114<br \/>\n**DESCRIPTION:** Apache Struts could allow a remote attacker to execute arbitrary code on the system, caused by the failure to restrict the setting of Class Loader attributes. An attacker could exploit this vulnerability using the class parameter of an ActionForm object to manipulate the ClassLoader and execute arbitrary code on the system.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/92889 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:L\/Au:N\/C:P\/I:P\/A:P)  <\/p>\n<p>**CVEID:**CVE-2019-10086<br \/>\n**DESCRIPTION:** Apache Commons Beanutils could allow a remote attacker to gain unauthorized access to the system, caused by the failure to suppresses the class property in bean introspection by default. An attacker could exploit this vulnerability to gain unauthorized access to the classloader.<br \/>\nCVSS Base score: 5.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/166353 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2019-10202<br \/>\n**DESCRIPTION:** Red Hat JBoss Enterprise Application Platform (EAP) could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization in Codehaus. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.<br \/>\nCVSS Base score: 8.1<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/168251 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)  <\/p>\n<p>**CVEID:**CVE-2019-10172<br \/>\n**DESCRIPTION:** Jackson-mapper-asl could allow a remote attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data. By sending a specially-crafted XML data, a remote attacker could exploit this vulnerability to obtain sensitive information.<br \/>\nCVSS Base score: 5.9<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/172436 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N)  <\/p>\n<p>**CVEID:**CVE-2019-17571<br \/>\n**DESCRIPTION:** Apache Log4j could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization of untrusted data in SocketServer. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.<br \/>\nCVSS Base score: 9.8<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/173314 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)  <\/p>\n<p>**CVEID:**CVE-2019-12402<br \/>\n**DESCRIPTION:** Apache Commons Compress is vulnerable to a denial of service, caused by an error in the internal file name encoding algorithm. By choosing the file names inside of a specially crafted archive, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.<br \/>\nCVSS Base score: 5.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/165956 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L)  <\/p>\n<p>**CVEID:**CVE-2017-3734<br \/>\n**DESCRIPTION:** ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.<br \/>\nCVSS Base score: 0<br \/>\nCVSS Vector:  <\/p>\n<p>**CVEID:**CVE-2019-16869<br \/>\n**DESCRIPTION:** Netty is vulnerable to HTTP request smuggling, caused by a flaw when handling unusual whitespaces before the colon in HTTP headers. By sending a specially-crafted request, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.<br \/>\nCVSS Base score: 6.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/167672 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N)  <\/p>\n<p>**CVEID:**CVE-2019-17195<br \/>\n**DESCRIPTION:** Connect2id Nimbus JOSE+JWT is vulnerable to a denial of service, caused by the throwing of various uncaught exceptions while parsing a JWT. An attacker could exploit this vulnerability to crash the application or obtain sensitive information.<br \/>\nCVSS Base score: 6.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/169514 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:L)  <\/p>\n<p>**CVEID:**CVE-2017-18640<br \/>\n**DESCRIPTION:** SnakeYAML is vulnerable to a denial of service, caused by an entity expansion in Alias feature during a load operation. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause the application to crash.<br \/>\nCVSS Base score: 5.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/174331 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L)  <\/p>\n<p>**CVEID:**CVE-2019-0201<br \/>\n**DESCRIPTION:** Apache ZooKeeper could allow a remote attacker to obtain sensitive information, caused by the failure to check permissions by the getACL() command. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information.<br \/>\nCVSS Base score: 7.5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/161303 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N)  <\/p>\n<p>**CVEID:**CVE-2014-3488<br \/>\n**DESCRIPTION:** Netty is vulnerable to a denial of service, caused by an error in SslHandler. A remote attacker could exploit this vulnerability using a specially-crafted SSLv2Hello message to exhaust all available CPU resources and cause the application to enter into an infinite loop.<br \/>\nCVSS Base score: 5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/95285 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:L\/Au:N\/C:N\/I:N\/A:P)  <\/p>\n<p>**CVEID:**CVE-2015-2156<br \/>\n**DESCRIPTION:** Netty could allow a remote attacker to bypass restrictions, caused by the improper validation of characters in a cookie name by the cookie parsing code. An attacker could exploit this vulnerability to bypass the HttpOnly flag in all Play applications and gain access to the system.<br \/>\nCVSS Base score: 6.4<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/103239 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:L\/Au:N\/C:P\/I:P\/A:N)  <\/p>\n<p>**CVEID:**CVE-2014-0193<br \/>\n**DESCRIPTION:** Netty is vulnerable to a denial of service, caused by an error in the WebSocket08FrameDecoder implementation. A remote attacker could exploit this vulnerability to exhaust all available memory resources.<br \/>\nCVSS Base score: 5<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/93006 for the current score.<br \/>\nCVSS Vector: (AV:N\/AC:L\/Au:N\/C:N\/I:N\/A:P)  <\/p>\n<p>**CVEID:**CVE-2017-12974<br \/>\n**DESCRIPTION:** Connect2id Nimbus JOSE+JWT could provide weaker than expected security, caused by proceeding with ECKey construction without ensuring that the public x and y coordinates are on the specified curve. A remote attacker could exploit this vulnerability to conduct an Invalid Curve Attack.<br \/>\nCVSS Base score: 7.3<br \/>\nCVSS Temporal Score: See:  https:\/\/exchange.xforce.ibmcloud.com\/vulnerabilities\/130788 for the current score.<br \/>\nCVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L)<\/p>\n<p>## Affected Products and Versions<\/p>\n<p>IBM PureData System for Operational Analytics V1.1 (A1801)<\/p>\n<p>## Remediation\/Fixes<\/p>\n<p>**IBM strongly recommends addressing the vulnerability now by doing the following:**<\/p>\n<p>Determine the appliance fixpack level as root on the management server using the appl_ls_cat command.<\/p>\n<p>$ appl_ls_cat -i<br \/>\nNAME VERSION STATUS DESCRIPTION<br \/>\nbwr3 4.0.8.0 Committed Updates for IBM_PureData_System_for_Operational_Analytics<\/p>\n<p>Determine the version of Db2 used on the core nodes in the appliance. The command below shows that Version 10.5.0.11 is installed. The number of hosts, Db2 version and instance name are customer dependent. The appliance supports Db2 10.5 or Db2 11.1 and the default instance owner is bcuaix. The command below shows that the instance is used Db2 10.5.0.11.<\/p>\n<p>$ dsh -n ${BCUALL} &#8216;\/usr\/local\/bin\/db2ls -c | grep -v &#8220;#&#8221; | cut -d: -f 1 | head -1 | while read p;do $p\/bin\/db2greg -dump | grep &#8220;^I&#8221;;done&#8217;| dshbak -c<br \/>\nHOSTS &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nhost02, host04, host05, hostflash06<br \/>\n\\&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nI,DB2,10.5.0.11,bcuaix,\/db2home\/bcuaix\/sqllib,,1,0,\/usr\/IBM\/dwe\/db2\/V10.5.0.11..2,,<\/p>\n<p>Login as the instance owner to any of the host servers. The following command will show the build number installed.<\/p>\n<p>$ db2level<br \/>\nDB21085I This instance or install (instance name, where applicable: &#8220;bcuaix&#8221;)<br \/>\nuses &#8220;64&#8221; bits and DB2 code release &#8220;SQL1005B&#8221; with level identifier<br \/>\n&#8220;060C010E&#8221;.<br \/>\nInformational tokens are &#8220;DB2 v10.5.0.11&#8221;, &#8220;special_40479&#8221;, &#8220;IP24071_40479&#8221;,<br \/>\nand Fix Pack &#8220;11&#8221;.<br \/>\nProduct is installed at &#8220;\/usr\/IBM\/dwe\/db2\/V10.5.0.11..2&#8221;.<\/p>\n<p>Use the table below to determine how to download the Db2 Fixpack or Special Build and then refer to the appliance technote https:\/\/www.ibm.com\/support\/pages\/installing-db2-fix-pack-ibm-puredata-system-operational-analytics for instructions on how to apply the Db2 Fixpack or Special Build on the appliance. Contact IBM Support for any questions or concerns related to this update. The number in brackets will match version returned by the appl_ls_conf command. <\/p>\n<p>Current V1.1 Fixpack Level | Remediation Options<br \/>\n&#8212;|&#8212;<br \/>\nV1.1 GA [ 4.0.4.x ] |  Validated stack is not vulnerable at this level.<br \/>\nV1.1 FP1 [ 4.0.5.x ] |  Validated stack is not vulnerable at this level.<br \/>\nV1.1 FP2 [ 4.0.6.x ] |  Validated stack is not vulnerable at this level.<br \/>\nV1.1 FP3 [ 4.0.7.x ] |  If using Db2 10.5, the system is not vulnerable. If using Db2 11.1, download the Db2 11.1 fixpack at: Db2 Version 11.1 Mod 4 Fix Pack 7 for Linux, UNIX, and Windows<br \/>\nV1.1 FP4 [ 4.0.8.x ] |  If using Db2 10.5, the system is not vulnerable. If using Db2 11.1, download the Db2 11.1 fixpack at: Db2 Version 11.1 Mod 4 Fix Pack 7 for Linux, UNIX, and Windows  <\/p>\n<p>## Workarounds and Mitigations<\/p>\n<p>None<\/p>\n<p>##\n        <\/p><\/div>\n<\/p><\/div>\n<div class=\"impact-section\">\n<h3>Impact Assessment<\/h3>\n<table class=\"impact-table\">\n<tr>\n<th>Base Score<\/th>\n<td>9.8<\/td>\n<\/tr>\n<tr>\n<th>Severity<\/th>\n<td style=\"color: #cc0000;\">CRITICAL<\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"source-link\">\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6605881\" target=\"_blank\">View full CVE details<\/a><\/p>\n<\/p><\/div>\n<\/div>\n<style>\n.vulnerability-details {\n    font-family: Arial, sans-serif;\n    max-width: 1200px;\n    margin: 0 auto;\n    padding: 20px;\n}<\/p>\n<p>.info-section, .cvss-section, .cve-section, .description-section, .impact-section {\n    margin-bottom: 30px;\n    background: #f8f9fa;\n    padding: 20px;\n    border-radius: 8px;\n    box-shadow: 0 2px 4px rgba(0,0,0,0.1);\n}<\/p>\n<p>h2 {\n    color: #2c3e50;\n    border-bottom: 2px solid #3498db;\n    padding-bottom: 10px;\n    margin-bottom: 20px;\n}<\/p>\n<p>h3 {\n    color: #34495e;\n    margin-bottom: 15px;\n}<\/p>\n<p>.info-table, .cvss-table, .cve-table, .impact-table {\n    width: 100%;\n    border-collapse: collapse;\n    margin-bottom: 20px;\n}<\/p>\n<p>.info-table th, .cvss-table th, .cve-table th, .impact-table th {\n    background: #e9ecef;\n    padding: 12px;\n    text-align: left;\n    width: 200px;\n}<\/p>\n<p>.info-table td, .cvss-table td, .cve-table td, .impact-table td {\n    padding: 12px;\n    border-bottom: 1px solid #dee2e6;\n}<\/p>\n<p>.description-content {\n    line-height: 1.6;\n    color: #2c3e50;\n}<\/p>\n<p>.source-link {\n    text-align: center;\n    margin-top: 30px;\n}<\/p>\n<p>.source-link a {\n    display: inline-block;\n    padding: 10px 20px;\n    background: #3498db;\n    color: white;\n    text-decoration: none;\n    border-radius: 5px;\n    transition: background 0.3s;\n}<\/p>\n<p>.source-link a:hover {\n    background: #2980b9;\n}\n<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability Details Basic Information Title Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics Type&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[9,6,8,35,12,76,13,7,11,5],"class_list":["post-2094","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-ibm","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=2094\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Vulnerability Details Basic Information Title Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics Type...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=2094\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-28T22:33:35+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2094#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2094\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics\",\"datePublished\":\"2025-04-28T22:33:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2094\"},\"wordCount\":2806,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"ibm\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=2094#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2094\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2094\",\"name\":\"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-04-28T22:33:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2094#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=2094\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=2094#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=2094","og_locale":"en_US","og_type":"article","og_title":"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics - zero redgem","og_description":"Vulnerability Details Basic Information Title Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics Type...","og_url":"https:\/\/zero.redgem.net\/?p=2094","og_site_name":"zero redgem","article_published_time":"2025-04-28T22:33:35+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=2094#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=2094"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics","datePublished":"2025-04-28T22:33:35+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=2094"},"wordCount":2806,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.8","exploit","ibm","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=2094#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=2094","url":"https:\/\/zero.redgem.net\/?p=2094","name":"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-04-28T22:33:35+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=2094#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=2094"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=2094#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Security Bulletin: Multiple security vulnerabilities have been identified in IBM\u00ae DB2\u00ae shipped with IBM PureData System for Operational Analytics"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/2094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2094"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/2094\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}