{"containers":{"cna":{"affected":[{"product":"DB2 for Linux, UNIX and Windows","vendor":"IBM","versions":[{"status":"affected","version":"10.5"},{"status":"affected","version":"10.1"},{"status":"affected","version":"9.7"},{"status":"affected","version":"11.1"},{"status":"affected","version":"11.5"}]}],"datePublic":"2021-12-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521."}],"metrics":[{"cvssV3_0":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","exploitCodeMaturity":"UNPROVEN","integrityImpact":"NONE","privilegesRequired":"NONE","remediationLevel":"OFFICIAL_FIX","reportConfidence":"CONFIRMED","scope":"UNCHANGED","temporalScore":5.2,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.0/UI:N/A:N/AC:H/I:N/PR:N/S:U/AV:N/C:H/RL:O/RC:C/E:U","version":"3.0"}}],"problemTypes":[{"descriptions":[{"description":"Obtain Information","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2022-02-25T09:06:18.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.ibm.com/support/pages/node/6523804"},{"name":"ibm-db2-cve202120373-info-disc (195521)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/195521"},{"tags":["x_refsource_CONFIRM"],"url":"https://security.netapp.com/advisory/ntap-20220225-0005/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2021-12-08T00:00:00","ID":"CVE-2021-20373","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"DB2 for Linux, UNIX and Windows","version":{"version_data":[{"version_value":"10.5"},{"version_value":"10.1"},{"version_value":"9.7"},{"version_value":"11.1"},{"version_value":"11.5"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521."}]},"impact":{"cvssv3":{"BM":{"A":"N","AC":"H","AV":"N","C":"H","I":"N","PR":"N","S":"U","UI":"N"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"https://www.ibm.com/support/pages/node/6523804","refsource":"CONFIRM","title":"IBM Security Bulletin 6523804 (DB2 for Linux, UNIX and Windows)","url":"https://www.ibm.com/support/pages/node/6523804"},{"name":"ibm-db2-cve202120373-info-disc (195521)","refsource":"XF","title":"X-Force Vulnerability Report","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/195521"},{"name":"https://security.netapp.com/advisory/ntap-20220225-0005/","refsource":"CONFIRM","url":"https://security.netapp.com/advisory/ntap-20220225-0005/"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T17:37:24.345Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.ibm.com/support/pages/node/6523804"},{"name":"ibm-db2-cve202120373-info-disc (195521)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/195521"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://security.netapp.com/advisory/ntap-20220225-0005/"}]}]},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2021-20373","datePublished":"2021-12-09T17:00:24.045Z","dateReserved":"2020-12-17T00:00:00.000Z","dateUpdated":"2024-09-17T00:45:54.177Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}