PT-2018-12590 · Ibm · Ibm Db2

Rich Mirch

·

Published

2018-07-10

·

Updated

2019-10-09

·

CVE-2018-1458

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 9.7, 10.1, 10.5, and 11.1
Description The issue allows a local user to execute arbitrary code and conduct DLL hijacking attacks.
Recommendations For versions 9.7, 10.1, 10.5, and 11.1, update to a version that includes the fix for this issue to prevent arbitrary code execution and DLL hijacking attacks.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1458

Affected Products

Ibm Db2