PT-2018-12590 · Ibm · Ibm Db2

Rich Mirch

·

Publicado

2018-07-10

·

Atualizado

2019-10-09

·

CVE-2018-1458

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 9.7, 10.1, 10.5, and 11.1
Description The issue allows a local user to execute arbitrary code and conduct DLL hijacking attacks.
Recommendations For versions 9.7, 10.1, 10.5, and 11.1, update to a version that includes the fix for this issue to prevent arbitrary code execution and DLL hijacking attacks.

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1458

Produtos afetados

Ibm Db2