QID 20338
Date Published: 2023-05-10
QID 20338: IBM DB2 Privilege Escalation Vulnerability (1115943)
Db2 could allow a local authenticated attacker to gain elevated privileges on the system, caused by an unquoted search path in sshd_worker.exe. By inserting arbitrary file in the path, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges.
QID Detection Logic: Authenticated (Windows): This QID checks for vulnerable versions of DB2 on windows OS
Db2 is vulnerable to an privilege escalation vulnerability.
Solution
Please refer to the following links 1115943
Vendor References
- 1115943 -
www.ibm.com/support/pages/node/1115943
CVEs related to QID 20338
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 1115943 |
|