CVE-2023-47145: IBM DB2
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.
Affected products
- IBM DB2: from 10.5, before 10.5.0.11 (fixed in 10.5.0.11); from 11.1, before 11.1.4.7 (fixed in 11.1.4.7); from 11.5, before 11.5.8 (fixed in 11.5.8)
Published 2024-01-07. Last modified 2026-06-17.