QID 20224
Date Published: 2021-07-15
QID 20224: IBM DB2 Privilege Escalation Vulnerability(6466363)
DB2 is a family of data management products, including database servers, developed by IBM.
IBM Db2 could allow a local user to access and change the configuration of DB2 due to a race condition via a symbolic link.
Affected Versions:
IBM DB2 Prior to 11.5 M6FP0
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Successful exploit could allow a local user to access and change the configuration of DB2 due to a race condition of a symbolic link
Solution
Please refer to the following link 6466363 for more details.
Vendor References
- 6466363 -
www.ibm.com/support/pages/node/6466363
CVEs related to QID 20224
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6466363 |
|