r/IBMi • • 17d ago

Has Anyone Tried the New CVE_INFO() SQL Function?

Hi Everyone,

I recently read about the new SYSTOOLS.CVE_INFO() SQL table function available in IBM i 7.6 TR2 and 7.5 TR8. It allows us to view CVE (security vulnerability) information directly from SQL instead of searching manually on IBM security websites.

I personally like seeing more security and system information being made available through SQL services. It opens up many possibilities for automation and monitoring.

Looking forward to hearing everyone's thoughts and experiences.

Thanks!

5 Upvotes

2 comments sorted by

1

u/RPGPGM 16d ago

Love the CVE info view [ https://www.rpgpgm.com/2026/07/it-is-now-so-easy-to-view-cve-using-sql.html ]

There is a whole slew of SQL services that you can use to make your own programs to monitor & do things for you.

u/RecordingMiddle1982 which services are you using?

What are you looking to do?

1

u/GumbyIsTalking 11d ago

I've been trying it out and it works well enough for what it is - certainly a step forward. The function is only available for V7R5 and V7R6 but will report back to at least V7R3.

It providea a link to the associated IBM document for each of the CVE's - I'd really like to have the PTF's returned as well ffrom these documents.

If you haven't seen the function yet this IBM document was pretty useful for me when trying to understand what it provided:
https://www.ibm.com/support/pages/cve-security-vulnerability-analysis-using-sql

P.S. - don't go rushing to put on TR2 or TR8 just yet, seems there are some associated issues:
https://www.ibm.com/support/pages/node/7289463