CVE-2018-1487: High severity ibm db2 universal database vulnerability
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1487?
CVE-2018-1487 has a medium severity, as it allows low privilege users to access the DB2 instance account.
How do I fix CVE-2018-1487?
To fix CVE-2018-1487, ensure that the shared libraries are loaded from trusted paths only.
What systems are affected by CVE-2018-1487?
CVE-2018-1487 affects IBM DB2 for Linux, UNIX, and Windows versions 9.7, 10.1, 10.5, and 11.1.
Can CVE-2018-1487 be exploited remotely?
CVE-2018-1487 does not require remote access to exploit; it can potentially be exploited locally by low privilege users.
What are the potential consequences of CVE-2018-1487?
The consequences of CVE-2018-1487 include unauthorized access to the DB2 instance, allowing attackers to execute malicious operations.