CVE-2020-5025: Buffer Overflow
Published Mar 11, 2021
·Updated
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 193661.
Affected Software
36 affected components
IBM DB2>=11.1.0.0<11.1.4.6
IBM DB2>=11.5<11.5.5.0
IBM DB2=9.7
IBM DB2=9.7-fp1
IBM DB2=9.7-fp10
IBM DB2=9.7-fp2
IBM DB2=9.7-fp3
IBM DB2=9.7-fp3a
IBM DB2=9.7-fp4
IBM DB2=9.7-fp5
IBM DB2=9.7-fp6
IBM DB2=9.7-fp7
IBM DB2=9.7-fp8
IBM DB2=9.7-fp9
IBM DB2=9.7-fp9a
IBM DB2=10.1
IBM DB2=10.1-fp1
IBM DB2=10.1-fp2
IBM DB2=10.1-fp3
IBM DB2=10.1-fp3a
IBM DB2=10.1-fp4
IBM DB2=10.1-fp5
IBM DB2=10.5
IBM DB2=10.5-fp1
IBM DB2=10.5-fp2
IBM DB2=10.5-fp3
IBM DB2=10.5-fp3a
IBM DB2=10.5-fp4
IBM DB2=10.5-fp5
IBM DB2=10.5-fp6
IBM DB2=10.5-fp7
IBM DB2=10.5-fp8
IBM DB2=10.5-fp9
Linux Linux kernel
Microsoft Windows
NetApp OnCommand Insight
Event History
Mar 11, 2021
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5025?
The severity of CVE-2020-5025 is high.
2
How does CVE-2020-5025 affect IBM DB2?
CVE-2020-5025 affects IBM DB2 for Linux, UNIX, and Windows versions 9.7, 10.1, 10.5, 11.1, and 11.5.
3
What is the vulnerability type of CVE-2020-5025?
The vulnerability type of CVE-2020-5025 is a buffer overflow.
4
How can a local attacker exploit CVE-2020-5025?
A local attacker can exploit CVE-2020-5025 by leveraging improper bounds checking to execute arbitrary code on the system with root privileges.
5
Is NetApp OnCommand Insight affected by CVE-2020-5025?
No, NetApp OnCommand Insight is not affected by CVE-2020-5025.