Privilege Escalation in IBM DB2 High Performance Unload for LUW
CVE-2019-4447
8.4HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 26 August 2019
Summary
IBM DB2 High Performance Unload for LUW has a security vulnerability due to a setuid root binary, db2hpum_debug, which improperly trusts the PATH environment variable. A low privilege user can exploit this by modifying the PATH variable to redirect commands to a user-controlled location. This attacker could then induce a crash, triggering execution of malicious commands with root privileges, thereby posing a significant security risk.
Affected Version(s)
DB2 High Performance Unload load for LUW 6.1
DB2 High Performance Unload load for LUW 6.1.0.1
DB2 High Performance Unload load for LUW 6.1.0.1IF1
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved