CVE-2019-4015: Buffer Overflow
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155893.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4015?
CVE-2019-4015 is classified as a high severity vulnerability due to its potential for allowing authenticated local attackers to execute arbitrary code as root.
How do I fix CVE-2019-4015?
To remediate CVE-2019-4015, upgrade IBM DB2 to a version that is not impacted by this buffer overflow vulnerability.
Who is affected by CVE-2019-4015?
CVE-2019-4015 affects users of IBM DB2 versions 9.7, 10.1, 10.5, and 11.1 on Linux, UNIX, and Windows platforms.
What types of attacks are possible with CVE-2019-4015?
CVE-2019-4015 allows authenticated local attackers to potentially execute arbitrary code, leading to full compromise of the affected system.
Is CVE-2019-4015 a local or remote vulnerability?
CVE-2019-4015 is a local vulnerability, meaning it requires an authenticated user already on the system to exploit.