QID 20332
Date Published: 2023-05-03
QID 20332: IBM DB2 Privilege Escalation Vulnerability (2878809)
IBM Db2 may be vulnerable to a denial of service when executing a specially crafted 'Load' command.
Affected Versions:
Up to Version v11.1.4FP6
Up to Version V11.5 GA
QID Detection Logic:
Authenticated (DB2):
This QID queries the DB2 server to get the server version and fix pack level and checks to see if it's vulnerable.
Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS
An authenticated local attacker with special permissions can execute specially crafted Db2 commands to modify the owner of stored procedures to SYSIBM, causing a privilege escalation.
Solution
Please refer to the following links 2878809
Vendor References
- 2878809 -
www.ibm.com/support/pages/node/2878809
CVEs related to QID 20332
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2878809 |
|