First published: Tue Oct 28 2003(Updated: )
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =7.1 | |
IBM DB2 Universal Database | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0898 is classified as a moderate severity vulnerability that allows local users to escalate privileges.
To fix CVE-2003-0898, upgrade IBM DB2 to version 7.2 FixPak 10a or later.
CVE-2003-0898 affects IBM DB2 version 7.1 and 7.2 prior to FixPak 10a.
A symlink attack involves creating a symbolic link that tricks the DB2 applications into overwriting arbitrary files.
CVE-2003-0898 is a local vulnerability that requires access to the affected system for exploitation.