First published: Fri Nov 09 2018(Updated: )
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 149640.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.7 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.5 | |
IBM Db2 | =11.1 | |
Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1802 is considered a high-severity vulnerability due to its potential to allow unprivileged users to gain full access to the DB2 instance account.
To fix CVE-2018-1802, ensure that shared libraries are loaded from trusted paths and apply the latest security updates provided by IBM.
CVE-2018-1802 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1 running on Linux, UNIX, and Windows.
If exploited, CVE-2018-1802 could allow a low-privilege user to execute arbitrary code with the privileges of the DB2 instance account.
CVE-2018-1802 was published on December 31, 2018.