IBM Security Bulletin: IBM® Db2® is vulnerable to privilege escalation via loading libraries from an untrusted path (CVE-2018-1802).

Nov 7, 2018 8:02 am EST

Categorized: High Severity

Share this post:

Db2 binaries load shared libraries from an untrusted path, potentially giving Db2 Instance Owner root access.

CVE(s): CVE-2018-1802

Affected product(s) and affected version(s):

All fix pack levels of IBM Db2 V9.7, V10.1, V10.5, and V11.1 editions on all platforms except Windows are affected. Windows platforms are not affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10733122
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/149640



from IBM Product Security Incident Response Team https://ift.tt/2JLU8Xv