CVE-2020-4363: Buffer Overflow
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 178960.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4363?
CVE-2020-4363 has a high severity rating due to the potential for local attackers to execute arbitrary code with root privileges.
How do I fix CVE-2020-4363?
To mitigate CVE-2020-4363, apply the relevant security patches provided by IBM for the affected DB2 versions.
Which DB2 versions are affected by CVE-2020-4363?
CVE-2020-4363 affects IBM DB2 versions 9.7, 10.1, 10.5, 11.1, and 11.5.
Can CVE-2020-4363 be exploited remotely?
CVE-2020-4363 requires local access to exploit, as it is a local buffer overflow vulnerability.
What type of vulnerability is CVE-2020-4363?
CVE-2020-4363 is classified as a buffer overflow vulnerability caused by improper bounds checking.