CVE-2019-4101: Medium severity IBM DB2 vulnerability
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of service. Users that have both EXECUTE on PDGETDIAGHIST and access to the diagnostic directory on the DB2 server can cause the instance to crash. IBM X-Force ID: 158091.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4101?
CVE-2019-4101 is classified as a denial of service vulnerability affecting IBM DB2.
How do I fix CVE-2019-4101?
To address CVE-2019-4101, ensure that appropriate access controls are implemented to restrict EXECUTE permissions on PD_GET_DIAG_HIST.
Which versions of IBM DB2 are affected by CVE-2019-4101?
CVE-2019-4101 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1.
What type of attack does CVE-2019-4101 enable?
CVE-2019-4101 enables an attacker to cause a denial of service by exploiting the database instance.
Is it possible to mitigate the impact of CVE-2019-4101?
Yes, limiting user permissions and monitoring database access can help mitigate the impact of CVE-2019-4101.