CVE-2016-5995: High severity ibm db2 universal database vulnerability
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5995?
CVE-2016-5995 is classified as a medium severity vulnerability, allowing local users to gain privileges.
How do I fix CVE-2016-5995?
To fix CVE-2016-5995, update IBM DB2 to the latest version or apply the security patches provided by IBM.
Which versions of IBM DB2 are affected by CVE-2016-5995?
CVE-2016-5995 affects IBM DB2 versions 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX.
What type of vulnerability is CVE-2016-5995?
CVE-2016-5995 is an untrusted search path vulnerability that can be exploited through Trojan horse libraries.
Who can exploit CVE-2016-5995?
CVE-2016-5995 can be exploited by local users who have access to setuid or setgid programs.