CVE-2020-4414: Medium severity IBM DB2 vulnerability
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service. IBM X-Force ID: 179989.
Other sources
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4414.
What software versions are affected by this vulnerability?
IBM DB2 for Linux, UNIX and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5 are affected by this vulnerability.
What is the severity rating of CVE-2020-4414?
CVE-2020-4414 has a severity rating of medium (5.1).
What actions can an attacker perform with this vulnerability?
An attacker can perform unauthorized actions on the system by exploiting this vulnerability.
Is there a fix available for this vulnerability?
Yes, IBM has provided a fix for this vulnerability. Please refer to the IBM support page for more information.