CVE-2020-4739: High severity IBM db2 vulnerability
IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 188149.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4739?
CVE-2020-4739 has a high severity rating due to its potential to allow local authenticated attackers to execute arbitrary code.
How do I fix CVE-2020-4739?
To fix CVE-2020-4739, update your IBM Db2 version to the latest version available that addresses this vulnerability.
What systems are affected by CVE-2020-4739?
CVE-2020-4739 affects IBM Db2 Accessories Suite and DB2 for Linux, UNIX, and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5.
Can CVE-2020-4739 be exploited remotely?
No, CVE-2020-4739 can only be exploited by a local authenticated attacker.
Is CVE-2020-4739 related to Microsoft Windows?
Yes, CVE-2020-4739 is caused by a DLL search order hijacking vulnerability that is related to Microsoft Windows.