1.1.1 Install Available Updates

Information

Periodically, IBM releases updates for its Db2 11 products in the form of modification packs, fix packs, and interim fix packs. All updates are cumulative and contain the contents of the previous updates provided.

It is recommended that you review the available updates for Db2 11 on a regular and frequent basis and, optionally, subscribe for notification of critical Db2 fixes.

Db2 11.1 specifics

Modification packs contain new features as well as defect fixes and are indicated by a change in the modification and fix pack numbers in the product identifier (e.g. Db2 11.1.4.5 is modification pack 4 for Db2 11.1). Fix packs contain only defect fixes and are indicated by a change in just the fix pack number in the product identifier (e.g. Db2 11.1.4.5 is fix pack 5 for Db2 11.1). Interim fix packs contain only critical defect fixes (e.g. HIPER and security vulnerabilities) made available since the last modification or fix pack released and are identified by an 'iFixNN' suffix, where NN is the number of the interim fix.

Db2 11.5 specifics

Modification packs contain new features as well as defect fixes and are indicated by a change in the modification number in the product identifier (e.g. Db2 11.5.4.0 is modification pack 4 for Db2 11.5). Fix packs contain only defect fixes and are indicated by a change in just the fix pack number in the product identifier (e.g. Db2 11.5.4.1 is fix pack 1 for modification 4 of Db2 11.5). Db2 11.5 does not provide Interim fix packs.

Rationale:

Being aware of the available updates and critical fixes helps you evaluate which Db2 update is the minimum level that you should use for your next system update. It will also help you understand the relative urgency of acquiring the latest Db2 fix pack to help protect the database from known vulnerabilities and reduce downtime that may otherwise result from functional defects.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Apply the latest fix pack as offered from IBM.

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.5

Plugin: IBM_DB2DB

Control ID: 2a3e6314cc2ebbaec7cb3c0ebc757440201400728cebc9882e7da2a5ea3ea3dd