First published: Fri Nov 09 2018(Updated: )
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.5 | |
IBM DB2 Universal Database | =11.1 | |
Linux Kernel | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1781 is considered a critical vulnerability because it allows a local user to gain root access through a symbolic link attack.
To fix CVE-2018-1781, apply the latest patches and updates provided by IBM for affected DB2 versions.
The affected versions include IBM DB2 for Linux, UNIX, and Windows 9.7, 10.1, 10.5, and 11.1.
No, CVE-2018-1781 requires local access to the system for exploitation.
If successfully exploited, CVE-2018-1781 could allow an attacker to read, write, or corrupt files that they do not have permission to access.