CVE-2018-1980: Buffer Overflow
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1980?
CVE-2018-1980 has a high severity level due to its potential to allow authenticated local attackers to execute arbitrary code as root.
Who is affected by CVE-2018-1980?
CVE-2018-1980 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1 on Linux, UNIX, and Windows platforms.
How do I fix CVE-2018-1980?
To fix CVE-2018-1980, you should apply the latest security patches provided by IBM for the affected DB2 versions.
What is the exploit vector for CVE-2018-1980?
CVE-2018-1980 can be exploited by an authenticated local attacker who has access to the vulnerable DB2 application.
Is CVE-2018-1980 present in all IBM DB2 installations?
No, CVE-2018-1980 is only present in specific versions of IBM DB2, namely 9.7, 10.1, 10.5, and 11.1.