PT-2018-3330 · Ibm · Ibm Db2

Published

2018-09-18

·

Updated

2019-10-09

·

CVE-2018-1711

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 9.7, 10.1, 10.5, and 11.1
Description: The issue is related to errors in privilege management within the IBM DB2 database management system. Exploitation of this issue could allow an attacker to elevate their privileges. A local user may be able to gain privileges due to the ability to modify columns of existing tasks.
Recommendations: For IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 9.7, 10.1, 10.5, and 11.1, consider restricting access to task modification to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04861
CVE-2018-1711

Affected Products

Ibm Db2