CVE-2020-4386: Race Condition
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179268.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4386?
The severity of CVE-2020-4386 is medium.
How does CVE-2020-4386 affect IBM DB2 for Linux, UNIX and Windows?
CVE-2020-4386 allows a local user to obtain sensitive information using a race condition of a symbolic link in IBM DB2 for Linux, UNIX and Windows.
Which versions of IBM DB2 for Linux, UNIX and Windows are affected by CVE-2020-4386?
IBM DB2 for Linux, UNIX and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5 are affected by CVE-2020-4386.
Is Linux Linux kernel or Microsoft Windows vulnerable to CVE-2020-4386?
No, Linux Linux kernel and Microsoft Windows are not vulnerable to CVE-2020-4386.
Where can I find more information about CVE-2020-4386?
More information about CVE-2020-4386 can be found at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/179268) [Link 2](https://www.ibm.com/support/pages/node/6242342)