Information disclosure in IBM DB2 - CVE-2022-22390
Published: June 24, 2022
Vulnerability identifier: #VU64650
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22390
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper privilege management when table function is used. A local attacker can gain unauthorized access to sensitive information on the system.
Affected software
IBM DB2
IBM PureData System for Operational Analytics
IBM Cloud Pak System
IBM PureData System for Operational Analytics
IBM Cloud Pak System
How to mitigate CVE-2022-22390
Install updates from vendor's website.
IBM DB2 - addressed in versions 9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7, 11.5.7
IBM Cloud Pak System - update to 2.3.3.6
IBM Cloud Pak System - update to 2.3.3.6