CVE-2018-1834: High severity ibm db2 universal database vulnerability
Published Nov 9, 2018
·Updated
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.
Affected Software
6 affected components
IBM DB2=9.7
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=11.1
Linux Linux kernel
Microsoft Windows
Event History
Nov 9, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1834?
CVE-2018-1834 is classified as a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2018-1834?
To fix CVE-2018-1834, upgrade IBM DB2 to a patched version that addresses this vulnerability.
3
Who is affected by CVE-2018-1834?
CVE-2018-1834 affects local users of IBM DB2 versions 9.7, 10.1, 10.5, and 11.1 on Linux, UNIX, and Windows platforms.
4
What kind of attack does CVE-2018-1834 involve?
CVE-2018-1834 involves a symbolic link attack that can lead to privilege escalation on the affected systems.
5
Can CVE-2018-1834 be exploited remotely?
No, CVE-2018-1834 requires local access for exploitation.