CVE-2018-1781

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.

Published : 2018-11-09 01:29 Updated : 2019-10-09 23:39

7.2
CVSS Score More info
Score 7.2 / 10
7.2
Vendor Product Version URI
Ibm Db2 9.7 cpe:/a:ibm:db2:9.7
Ibm Db2 10.1 cpe:/a:ibm:db2:10.1
Ibm Db2 10.5 cpe:/a:ibm:db2:10.5
Ibm Db2 11.1 cpe:/a:ibm:db2:11.1
  1. Ibm (1) Search CVE
    1. Db2 (4) Search CVE
      1. 9.7
      2. 10.1
      3. 10.5
      4. 11.1

CWE

ID Name Description Links
CWE-59 Improper Link Resolution Before File Access ('Link Following') The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource. CVE

History of changes

Date Event
2018-12-12 17:46
2018-11-16 11:29
2018-11-14 11:29
2018-11-09 01:29

New CVE