CVE-2003-0898: Medium severity IBM DB2 Universal Database vulnerability
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DB2 7.2to a version that resolves this vulnerability.Patch FixPak 10a
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0898?
CVE-2003-0898 is classified as a moderate severity vulnerability that allows local users to escalate privileges.
How do I fix CVE-2003-0898?
To fix CVE-2003-0898, upgrade IBM DB2 to version 7.2 FixPak 10a or later.
What versions of IBM DB2 are affected by CVE-2003-0898?
CVE-2003-0898 affects IBM DB2 version 7.1 and 7.2 prior to FixPak 10a.
What is a symlink attack in the context of CVE-2003-0898?
A symlink attack involves creating a symbolic link that tricks the DB2 applications into overwriting arbitrary files.
Can CVE-2003-0898 be exploited remotely?
CVE-2003-0898 is a local vulnerability that requires access to the affected system for exploitation.