CVE-2021-38926: Medium severity ibm db2 universal database vulnerability
Published Dec 9, 2021
·Updated
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to gain privileges due to allowing modification of columns of existing tasks.
— IBM
Affected Software
11 affected components
IBM DB2=9.7
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=11.1
IBM DB2=11.5
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
NetApp OnCommand Insight
Event History
Dec 9, 2021
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Aug 4, 2024
Data Sourced
via IBM·02:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-38926.
2
What is the severity of CVE-2021-38926?
The severity of CVE-2021-38926 is medium (5.5).
3
Which versions of IBM Db2 for Linux, UNIX and Windows are affected by CVE-2021-38926?
IBM Db2 versions 9.7, 10.1, 10.5, 11.1, and 11.5 are affected by CVE-2021-38926.
4
How can a local user exploit CVE-2021-38926 to gain privileges?
A local user can exploit CVE-2021-38926 by allowing modification of columns of existing tasks.
5
Where can I find more information about CVE-2021-38926?
More information about CVE-2021-38926 can be found on the IBM X-Force ID: 210321.