CVE-2018-1781: High severity ibm db2 universal database vulnerability
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1781?
CVE-2018-1781 is considered a critical vulnerability because it allows a local user to gain root access through a symbolic link attack.
How do I fix CVE-2018-1781?
To fix CVE-2018-1781, apply the latest patches and updates provided by IBM for affected DB2 versions.
Which versions of IBM DB2 are affected by CVE-2018-1781?
The affected versions include IBM DB2 for Linux, UNIX, and Windows 9.7, 10.1, 10.5, and 11.1.
Can CVE-2018-1781 be exploited remotely?
No, CVE-2018-1781 requires local access to the system for exploitation.
What is the potential impact of CVE-2018-1781 if successfully exploited?
If successfully exploited, CVE-2018-1781 could allow an attacker to read, write, or corrupt files that they do not have permission to access.