Privilege Escalation in IBM DB2 High Performance Unload for LUW
CVE-2019-4447
8.4HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 26 August 2019
What is CVE-2019-4447?
IBM DB2 High Performance Unload for LUW has a security vulnerability due to a setuid root binary, db2hpum_debug, which improperly trusts the PATH environment variable. A low privilege user can exploit this by modifying the PATH variable to redirect commands to a user-controlled location. This attacker could then induce a crash, triggering execution of malicious commands with root privileges, thereby posing a significant security risk.
Affected Version(s)
DB2 High Performance Unload load for LUW 6.1
DB2 High Performance Unload load for LUW 6.1.0.1
DB2 High Performance Unload load for LUW 6.1.0.1IF1