PT-2018-12771 · Ibm · Db2

Rich Mirch

·

Published

2018-07-10

·

Updated

2019-10-09

·

CVE-2018-1487

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 9.7, 10.1, 10.5, and 11.1
Description The issue allows low privilege users to potentially gain full access to the DB2 instance account by loading a malicious shared library, as the binaries load shared libraries from an untrusted path.
Recommendations For versions 9.7, 10.1, 10.5, and 11.1, consider restricting access to the shared library loading mechanism to prevent malicious library loading until a patch is available. As a temporary workaround, restrict the ability of low privilege users to load shared libraries from untrusted paths.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1487

Affected Products

Db2