CVE-2023-47152

MEDIUM

IBM Db2 < 11.5.9 - Information Disclosure via Stack Trace

Title source: llm
STIX 2.1

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7105605

Scores

CVSS v3 5.9
EPSS 0.0058
EPSS Percentile 42.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
ibm/db2 < 11.5.9
Published Jan 22, 2024
Tracked Since Feb 18, 2026