CVE Database
/

CVE-2019-4448

Back to search

CVE-2019-4448

Published: Aug 26, 2019

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

8.4

HIGH

Description

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authority. IBM X-Force ID: 163489.

VendorProductVersions

IBM

DB2 High Performance Unload load for LUW

affected
6.1
affected
6.1.0.1
affected
6.1.0.1IF1
affected
6.1.0.2
affected
6.1.0.2IF1

+1 more versions

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/UI:N/S:U/AV:L/C:H/AC:L/A:H/PR:N/I:H/E:U/RC:C/RL:O

User Interaction

None

Scope

Unchanged

Attack Vector

Local

Confidentiality

High

Attack Complexity

Low

Availability

High

Privileges Required

None

Integrity

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now