Vulnerability Name: | CVE-2019-4057 (CCN-156567) | ||||||||||||
Assigned: | 2019-06-27 | ||||||||||||
Published: | 2019-06-27 | ||||||||||||
Updated: | 2022-12-09 | ||||||||||||
Summary: | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567. | ||||||||||||
CVSS v3 Severity: | 6.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-4057 Source: psirt@us.ibm.com Type: VDB Entry, Vendor Advisory psirt@us.ibm.com Source: XF Type: UNKNOWN ibm-db2-cve20194057-priv-escalation(156567) Source: CCN Type: IBM Security Bulletin 880735 (DB2 for Linux, UNIX and Windows) IBM Db2 is vulnerable to privilege escalation to root via malicious use of fenced user (CVE-2019-4057). Source: psirt@us.ibm.com Type: Vendor Advisory psirt@us.ibm.com Source: CCN Type: IBM Security Bulletin 1109853 (Spectrum Protect) Multiple Db2 vulnerabilities affect the IBM Spectrum Protect Server (CVE-2019-4057, CVE-2019-4101, CVE-2019-4154, CVE-2019-4386, CVE-2019-4322) Source: CCN Type: IBM Security Bulletin 6598029 (PureData System for Operational Analytics) Multiple vulnerabilities has been identified in IBM DB2 shipped with IBM PureData System for Operational Analytics | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |