PT-2018-3330 · Ibm · Ibm Db2
Publicado
2018-09-18
·
Atualizado
2019-10-09
·
CVE-2018-1711
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 9.7, 10.1, 10.5, and 11.1
Description:
The issue is related to errors in privilege management within the IBM DB2 database management system. Exploitation of this issue could allow an attacker to elevate their privileges. A local user may be able to gain privileges due to the ability to modify columns of existing tasks.
Recommendations:
For IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 9.7, 10.1, 10.5, and 11.1, consider restricting access to task modification to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Db2