CVE-2020-4387: Race Condition
Published Jul 1, 2020
·Updated
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179269.
Affected Software
7 affected components
IBM DB2=9.7.0.0
IBM DB2=10.1.0.0
IBM DB2=10.5.0.0
IBM DB2=11.1.0.0
IBM DB2=11.5.0.0
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Jul 1, 2020
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-4387?
CVE-2020-4387 is rated as a medium severity vulnerability.
2
How do I fix CVE-2020-4387?
To fix CVE-2020-4387, upgrade to a patched version of IBM DB2 that addresses this vulnerability.
3
Who is affected by CVE-2020-4387?
CVE-2020-4387 affects local users of IBM DB2 for Linux, UNIX, and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5.
4
What type of vulnerability is CVE-2020-4387?
CVE-2020-4387 is a local information disclosure vulnerability caused by a race condition with symbolic links.
5
What could result from CVE-2020-4387?
Exploitation of CVE-2020-4387 could allow a local user to access sensitive information from the affected system.