Client-Side Validation Bypass in IBM Db2 on Cloud Pak for Data
CVE-2023-33854

5.3MEDIUM

What is CVE-2023-33854?

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8 to 5.3 are susceptible to a vulnerability that enables authenticated users to circumvent client-side validation mechanisms. This flaw permits the manipulation of input data through man-in-the-middle techniques, potentially compromising the integrity of the data being processed and leading to unauthorized actions or data leaks.

Affected Version(s)

Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 4.8.0 <= 1.8.4

Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 5.0.0 <= 5.3.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.