Security Bulletin: Due to use of Spring Framework, IBM Db2 Web Query for i is vulnerable to unprotected fields (CVE-2022-22968), remote code execution (CVE-2022-22965), and denial of service (CVE-2022-22950).

There are multiple vulnerabilities in Spring Framework (CVE-2022-22968, CVE-2022-22965, and CVE-2022-22950) as described in the vulnerability details section. Spring Framework v5.3.8 is used by Db2 Web Query for i for infrastructure support. IBM has addressed the vulnerabilities in Db2 Web Query for i by upgrading to Spring Framework v5.3.19.

We’re off to Spain & can’t wait to see you at COMMON Europe! Stop by the Expo to learn how you can deliver DevOps to your organization, with trusted tools, beginning today! @CommonEurope #IBMi #DevOpsCommunity

We’re off to Spain & can’t wait to see you at COMMON Europe! Stop by the Expo to learn how you can deliver DevOps to your organization, with trusted tools, beginning today! @CommonEurope #IBMi #DevOpsCommunity pic.twitter.com/8ehjE0q1VO

– Midrange Dynamics (@MidrangDynamics)08:35 – Jun 09, 2022

#IBMi developers — Introducing 1/2-day Summit Deep Dive Workshops! Choose from 13 different skillsets focused on #SQL, #RPGLE, #API, #IBMiOSS or #Db2fori. Time for a skills upgrade! 😍

#IBMi developers — Introducing 1/2-day Summit Deep Dive Workshops! Choose from 13 different skillsets focused on #SQL, #RPGLE, #API, #IBMiOSS or #Db2fori. Time for a skills upgrade! 😍 ow.ly/a8vv50JsRvQ pic.twitter.com/BPN0lMY0Y1

– System i Developer (@SiDforIBMi)07:03 – Jun 09, 2022

Verified by MonsterInsights