CVE-2020-4701: Buffer Overflow
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.
Other sources
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4701?
CVE-2020-4701 is classified as a critical severity vulnerability due to the potential for local attackers to execute arbitrary code with root privileges.
How do I fix CVE-2020-4701?
To remediate CVE-2020-4701, update IBM DB2 to the latest fixed version as recommended by IBM's security advisory.
Who is affected by CVE-2020-4701?
CVE-2020-4701 affects IBM DB2 for Linux, UNIX, and Windows versions 10.5, 11.1, and 11.5.
Can CVE-2020-4701 be exploited remotely?
CVE-2020-4701 specifically requires local access to the system for exploitation.
What types of attacks can CVE-2020-4701 facilitate?
CVE-2020-4701 can enable local attackers to execute arbitrary code, potentially allowing them to take full control of the affected system.