PT-2015-5514 · Ibm · Db2+1
Published
2015-12-31
·
Updated
2018-10-09
·
CVE-2015-1947
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere BigInsights versions 3.0 through 3.0.0.2
IBM InfoSphere BigInsights version 4.0
Description
The issue allows local users to gain privileges via a Trojan horse library that is loaded by a setuid or setgid program when a DB2 database is used.
Recommendations
For IBM InfoSphere BigInsights versions 3.0 through 3.0.0.2, update to a version that is not affected by this issue.
For IBM InfoSphere BigInsights version 4.0, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting access to setuid or setgid programs to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Db2
Ibm Infosphere Biginsights