IBM has patched its ‘Db2 Web Query for I software against a variety of flaws inherited from other products.
According to IBM’s caution, Db2 Web Query for I generates logs and diagnostic traces using the insecure Apache Log4j, which required updating.
Another component, Apache Commons Compress, also has a vulnerability: CVE-2021-36090, which IBM identifies as a denial of service flaw caused by an out-of-memory error when significant quantities of memory are allocated.
A malicious ZIP archive can be used to attack services that use Compress’ zip package.
Tibco WebFOCUS, another susceptible programme used by the database software, is afflicted by a cross-site scripting vulnerability, CVE-2021-35493.
Once the URL is clicked, an attacker can use it to run scripts in the victim’s browser “inside the security context of the hosting Web site.”
According to IBM, “an attacker might exploit this vulnerability to obtain the victim’s cookie-based authentication credentials.”


