PT-2011-4834 · Ibm · Ibm Db2 Express Edition

Tim Brown

·

Published

2011-10-18

·

Updated

2018-10-11

·

CVE-2011-4061

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM DB2 Express Edition 9.7
Description The issue concerns untrusted search path vulnerabilities in the db2rspgn and kbbacf1 components of IBM DB2 Express Edition. This allows local users to gain privileges by utilizing a Trojan horse libkbb.so in the current working directory, related to the DT RPATH ELF header.
Recommendations For IBM DB2 Express Edition 9.7, consider restricting access to the db2rspgn and kbbacf1 components to minimize the risk of exploitation. As a temporary workaround, avoid using these components in untrusted environments until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-4061

Affected Products

Ibm Db2 Express Edition