CVE-2019-4094: High severity ibm db2 universal database vulnerability
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4094?
CVE-2019-4094 is classified as having a high severity due to its potential to grant low privilege users full root access.
How do I fix CVE-2019-4094?
To mitigate CVE-2019-4094, users should ensure that DB2 binaries are not allowed to load shared libraries from untrusted paths.
Who is affected by CVE-2019-4094?
CVE-2019-4094 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1 running on Linux, UNIX, and Windows.
What are the consequences of CVE-2019-4094?
The primary consequence of CVE-2019-4094 is that it allows a low privilege user to potentially gain full access to the system by loading a malicious library.
Is there a specific version of DB2 that is particularly vulnerable to CVE-2019-4094?
All affected versions of IBM DB2 from 9.7 to 11.1 are vulnerable to CVE-2019-4094 if they are configured to load shared libraries from untrusted paths.