First published: Tue Jul 10 2018(Updated: )
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.5 | |
IBM DB2 Universal Database | =11.1 | |
Linux Kernel | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1487 has a medium severity, as it allows low privilege users to access the DB2 instance account.
To fix CVE-2018-1487, ensure that the shared libraries are loaded from trusted paths only.
CVE-2018-1487 affects IBM DB2 for Linux, UNIX, and Windows versions 9.7, 10.1, 10.5, and 11.1.
CVE-2018-1487 does not require remote access to exploit; it can potentially be exploited locally by low privilege users.
The consequences of CVE-2018-1487 include unauthorized access to the DB2 instance, allowing attackers to execute malicious operations.