VYPR
Unrated severityNVD Advisory· Published Jan 22, 2024· Updated May 30, 2025

IBM Db2 information disclosure

CVE-2023-47152

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Db2 11.5 uses an insecure cryptographic algorithm and leaks stack-trace information under exceptional conditions, allowing attackers to obtain sensitive data.

Vulnerability

IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) version 11.5.x is vulnerable to an insecure cryptographic algorithm and information disclosure in stack traces under exceptional conditions [1]. The vulnerability affects the Db2 client and all platforms [1]. Specific details about the cryptographic weakness are not disclosed in the available references.

Exploitation

An attacker with network access can exploit the insecure cryptographic algorithm or trigger exceptional conditions that cause stack-trace information to be disclosed [1]. The CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) indicates that exploitation requires high attack complexity, no privileges, and no user interaction [1]. The exact steps to trigger the issue are not published.

Impact

A successful exploit leads to information disclosure, compromising confidentiality of data processed by the Db2 server [1]. The attack does not affect integrity or availability [1]. The CVSS confidentiality impact is rated High [1].

Mitigation

IBM provides special builds containing the interim fix for V11.5.9 and earlier fixpack levels; these are available from Fix Central [1]. Customers must contact Db2 support to obtain the updated db2jcc4.jar file [1]. The permanent fix is tracked as APAR DT255114 and will be included in a future fix pack [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.