{"containers":{"cna":{"affected":[{"product":"DB2 for Linux, UNIX and Windows","vendor":"IBM","versions":[{"status":"affected","version":"10.5"},{"status":"affected","version":"10.1"},{"status":"affected","version":"9.7"},{"status":"affected","version":"11.1"},{"status":"affected","version":"11.5"}]}],"datePublic":"2022-06-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973."}],"metrics":[{"cvssV3_0":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6.2,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","exploitCodeMaturity":"UNPROVEN","integrityImpact":"NONE","privilegesRequired":"NONE","remediationLevel":"OFFICIAL_FIX","reportConfidence":"CONFIRMED","scope":"UNCHANGED","temporalScore":5.4,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.0/AC:L/PR:N/UI:N/A:N/C:H/I:N/S:U/AV:L/RC:C/E:U/RL:O","version":"3.0"}}],"problemTypes":[{"descriptions":[{"description":"Obtain Information","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2022-07-29T19:07:39.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.ibm.com/support/pages/node/6597993"},{"name":"ibm-db2-cve202222390-info-disc (221973)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/221973"},{"tags":["x_refsource_CONFIRM"],"url":"https://security.netapp.com/advisory/ntap-20220729-0007/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2022-06-23T00:00:00","ID":"CVE-2022-22390","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"DB2 for Linux, UNIX and Windows","version":{"version_data":[{"version_value":"10.5"},{"version_value":"10.1"},{"version_value":"9.7"},{"version_value":"11.1"},{"version_value":"11.5"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973."}]},"impact":{"cvssv3":{"BM":{"A":"N","AC":"L","AV":"L","C":"H","I":"N","PR":"N","S":"U","UI":"N"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"https://www.ibm.com/support/pages/node/6597993","refsource":"CONFIRM","title":"IBM Security Bulletin 6597993 (DB2 for Linux, UNIX and Windows)","url":"https://www.ibm.com/support/pages/node/6597993"},{"name":"ibm-db2-cve202222390-info-disc (221973)","refsource":"XF","title":"X-Force Vulnerability Report","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/221973"},{"name":"https://security.netapp.com/advisory/ntap-20220729-0007/","refsource":"CONFIRM","url":"https://security.netapp.com/advisory/ntap-20220729-0007/"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T03:14:54.684Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.ibm.com/support/pages/node/6597993"},{"name":"ibm-db2-cve202222390-info-disc (221973)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/221973"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://security.netapp.com/advisory/ntap-20220729-0007/"}]}]},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2022-22390","datePublished":"2022-06-24T16:45:19.526Z","dateReserved":"2022-01-03T00:00:00.000Z","dateUpdated":"2024-09-16T16:43:54.489Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}