{
  "document" : {
    "aggregate_severity" : {
      "text" : "mittel"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "IBM DB2 ist ein relationales Datenbanksystem (RDBS) von IBM.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein entfernter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Linux\n- Sonstiges\n- Windows",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2024-0022 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0022.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2024-0022 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0022"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105503 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105503"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105501 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105501"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105497 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105497"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105496 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105496"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105505 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105505"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105502 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105502"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105506 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105506"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105605 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105605"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7105499 vom 2024-01-08",
      "url" : "https://www.ibm.com/support/pages/node/7105499"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7109988 vom 2024-01-23",
      "url" : "https://www.ibm.com/support/pages/node/7109988"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7118327 vom 2024-02-15",
      "url" : "https://www.ibm.com/support/pages/node/7118327"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7145753 vom 2024-04-02",
      "url" : "https://www.ibm.com/support/pages/node/7145753"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7150158 vom 2024-05-03",
      "url" : "https://www.ibm.com/support/pages/node/7150158"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7180281 vom 2025-01-04",
      "url" : "https://www.ibm.com/support/pages/node/7180281"
    } ],
    "source_lang" : "en-US",
    "title" : "IBM DB2: Mehrere Schwachstellen",
    "tracking" : {
      "current_release_date" : "2025-01-05T23:00:00.000+00:00",
      "generator" : {
        "date" : "2025-01-06T09:02:27.192+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.3.10"
        }
      },
      "id" : "WID-SEC-W-2024-0022",
      "initial_release_date" : "2024-01-08T23:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2024-01-08T23:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      }, {
        "date" : "2024-01-23T23:00:00.000+00:00",
        "number" : "2",
        "summary" : "Neue Updates von IBM aufgenommen"
      }, {
        "date" : "2024-02-15T23:00:00.000+00:00",
        "number" : "3",
        "summary" : "Neue Updates von IBM aufgenommen"
      }, {
        "date" : "2024-04-02T22:00:00.000+00:00",
        "number" : "4",
        "summary" : "Neue Updates von IBM aufgenommen"
      }, {
        "date" : "2024-05-05T22:00:00.000+00:00",
        "number" : "5",
        "summary" : "Neue Updates von IBM aufgenommen"
      }, {
        "date" : "2025-01-05T23:00:00.000+00:00",
        "number" : "6",
        "summary" : "Neue Updates von IBM aufgenommen"
      } ],
      "status" : "final",
      "version" : "6"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_name",
          "name" : "IBM DB2",
          "product" : {
            "name" : "IBM DB2",
            "product_id" : "5104",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:-"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Big SQL",
          "product" : {
            "name" : "IBM DB2 Big SQL",
            "product_id" : "T022379",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:big_sql"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<10.5 FP11",
          "product" : {
            "name" : "IBM DB2 <10.5 FP11",
            "product_id" : "T031902"
          }
        }, {
          "category" : "product_version",
          "name" : "10.5 FP11",
          "product" : {
            "name" : "IBM DB2 10.5 FP11",
            "product_id" : "T031902-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:10.5_fp11"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<11.1.4 FP7",
          "product" : {
            "name" : "IBM DB2 <11.1.4 FP7",
            "product_id" : "T031903"
          }
        }, {
          "category" : "product_version",
          "name" : "11.1.4 FP7",
          "product" : {
            "name" : "IBM DB2 11.1.4 FP7",
            "product_id" : "T031903-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:11.1.4_fp7"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<11.5.9",
          "product" : {
            "name" : "IBM DB2 <11.5.9",
            "product_id" : "T031905"
          }
        }, {
          "category" : "product_version",
          "name" : "11.5.9",
          "product" : {
            "name" : "IBM DB2 11.5.9",
            "product_id" : "T031905-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:11.5.9"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "DB2"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "9.2",
          "product" : {
            "name" : "IBM License Metric Tool 9.2",
            "product_id" : "T027649",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:license_metric_tool:9.2"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "License Metric Tool"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "Key Lifecycle Manager 3.0",
          "product" : {
            "name" : "IBM Security Guardium Key Lifecycle Manager 3.0",
            "product_id" : "T021011",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:security_guardium:key_lifecycle_manager_3.0"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Key Lifecycle Manager 4.1.1",
          "product" : {
            "name" : "IBM Security Guardium Key Lifecycle Manager 4.1.1",
            "product_id" : "T021015",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:security_guardium:key_lifecycle_manager_4.1.1"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Key Lifecycle Manager 4.1",
          "product" : {
            "name" : "IBM Security Guardium Key Lifecycle Manager 4.1",
            "product_id" : "T021031",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:security_guardium:key_lifecycle_manager_4.1"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Key Lifecycle Manager 4.2",
          "product" : {
            "name" : "IBM Security Guardium Key Lifecycle Manager 4.2",
            "product_id" : "T027545",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:security_guardium:key_lifecycle_manager_4.2"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Key Lifecycle Manager 3.0.1",
          "product" : {
            "name" : "IBM Security Guardium Key Lifecycle Manager 3.0.1",
            "product_id" : "T029693",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:security_guardium:key_lifecycle_manager_3.0.1"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Key Lifecycle Manager 4.0",
          "product" : {
            "name" : "IBM Security Guardium Key Lifecycle Manager 4.0",
            "product_id" : "T029694",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:security_guardium:key_lifecycle_manager_4.0"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Key Lifecycle Manager 4.2.1",
          "product" : {
            "name" : "IBM Security Guardium Key Lifecycle Manager 4.2.1",
            "product_id" : "T032873",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:security_guardium:key_lifecycle_manager_4.2.1"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Security Guardium"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "6.2.0",
          "product" : {
            "name" : "IBM Tivoli Business Service Manager 6.2.0",
            "product_id" : "T014092",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:tivoli_business_service_manager:6.2.0"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Tivoli Business Service Manager"
      } ],
      "category" : "vendor",
      "name" : "IBM"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2023-27859",
    "notes" : [ {
      "category" : "description",
      "text" : "Es besteht eine Schwachstelle in IBM DB2. Durch die Installation einer bösartigen jar-Datei, die die bestehende gleichnamige jar-Datei in einer anderen Datenbank überschreibt, kann ein entfernter, authentifizierter Angreifer diese Schwachstelle zur Ausführung von beliebigem Code ausnutzen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T029693", "T032873", "T021015", "T014092", "T027649", "T022379", "5104", "T021031", "T031902", "T027545", "T031903", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-27859"
  }, {
    "cve" : "CVE-2023-45193",
    "notes" : [ {
      "category" : "description",
      "text" : "Es besteht eine Schwachstelle in IBM DB2. Durch die Verwendung eines speziell gestalteten Cursors kann ein entfernter, anonymer Angreifer diese Schwachstelle ausnutzen, um einen Denial-of-Service-Zustand zu verursachen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-45193"
  }, {
    "cve" : "CVE-2023-47141",
    "notes" : [ {
      "category" : "description",
      "text" : "Es bestehen mehrere Schwachstellen in IBM DB2. Durch eine speziell gestaltete Abfrage kann ein entfernter, authentifizierter Angreifer mit CONNECT-Rechten diese Schwachstellen ausnutzen, um einen Denial-of-Service-Zustand zu verursachen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-47141"
  }, {
    "cve" : "CVE-2023-47158",
    "notes" : [ {
      "category" : "description",
      "text" : "Es bestehen mehrere Schwachstellen in IBM DB2. Durch eine speziell gestaltete Abfrage kann ein entfernter, authentifizierter Angreifer mit CONNECT-Rechten diese Schwachstellen ausnutzen, um einen Denial-of-Service-Zustand zu verursachen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-47158"
  }, {
    "cve" : "CVE-2023-47746",
    "notes" : [ {
      "category" : "description",
      "text" : "Es bestehen mehrere Schwachstellen in IBM DB2. Durch eine speziell gestaltete Abfrage kann ein entfernter, authentifizierter Angreifer mit CONNECT-Rechten diese Schwachstellen ausnutzen, um einen Denial-of-Service-Zustand zu verursachen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-47746"
  }, {
    "cve" : "CVE-2023-47747",
    "notes" : [ {
      "category" : "description",
      "text" : "Es bestehen mehrere Schwachstellen in IBM DB2. Durch eine speziell gestaltete Abfrage kann ein entfernter, authentifizierter Angreifer mit CONNECT-Rechten diese Schwachstellen ausnutzen, um einen Denial-of-Service-Zustand zu verursachen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-47747"
  }, {
    "cve" : "CVE-2023-47152",
    "notes" : [ {
      "category" : "description",
      "text" : "Es besteht eine Schwachstelle in IBM DB2. Dieser Fehler besteht aufgrund eines unsicheren Verschlüsselungsalgorithmus. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um vertrauliche Informationen offenzulegen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-47152"
  }, {
    "cve" : "CVE-2023-50308",
    "notes" : [ {
      "category" : "description",
      "text" : "Es besteht eine Schwachstelle in IBM DB2. Unter bestimmten Umständen erlaubt dieser Fehler einem entfernten, authentifizierten Angreifer, einen Denial-of-Service-Zustand auszulösen, indem er eine Anweisung auf spaltenförmigen Tabellen ausführt."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00",
    "title" : "CVE-2023-50308"
  }, {
    "notes" : [ {
      "category" : "description",
      "text" : "Es besteht eine Schwachstelle in IBM DB2. Dieser Fehler besteht in der opensource presto-jdbc library aufgrund einer unsachgemäßen Validierung des nextUri Parameters, was zu einem serverseitigen Request Forgery Problem führt. Durch Senden einer speziell gestalteten Anfrage kann ein entfernter, authentifizierter Angreifer diese Schwachstelle ausnutzen, um vertrauliche Informationen offenzulegen."
    } ],
    "product_status" : {
      "known_affected" : [ "T029694", "T021015", "T029693", "T032873", "T014092", "T027649", "T022379", "5104", "T021031", "T027545", "T031905", "T021011" ]
    },
    "release_date" : "2024-01-08T23:00:00.000+00:00"
  } ]
}