CVE-2020-4885: Race Condition
Published Jun 24, 2021
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.
Affected Software
3 affected components
IBM DB2=11.5
IBM AIX
Linux Linux kernel
Remediation
Patch Available
Event History
Jun 24, 2021
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-4885?
The severity of CVE-2020-4885 is medium with a severity value of 4.7.
2
What software versions are affected by CVE-2020-4885?
IBM Db2 for Linux, UNIX, and Windows version 11.5 is affected by CVE-2020-4885.
3
How can a local user exploit CVE-2020-4885?
A local user can exploit CVE-2020-4885 to access and change the configuration of Db2 through a race condition of a symbolic link.
4
Is IBM AIX vulnerable to CVE-2020-4885?
No, IBM AIX is not vulnerable to CVE-2020-4885.
5
Is Linux Linux kernel vulnerable to CVE-2020-4885?
No, Linux Linux kernel is not vulnerable to CVE-2020-4885.