Privilege Escalation in IBM DB2 High Performance Unload for LUW
CVE-2019-4447

8.4HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 August 2019

Summary

IBM DB2 High Performance Unload for LUW has a security vulnerability due to a setuid root binary, db2hpum_debug, which improperly trusts the PATH environment variable. A low privilege user can exploit this by modifying the PATH variable to redirect commands to a user-controlled location. This attacker could then induce a crash, triggering execution of malicious commands with root privileges, thereby posing a significant security risk.

Affected Version(s)

DB2 High Performance Unload load for LUW 6.1

DB2 High Performance Unload load for LUW 6.1.0.1

DB2 High Performance Unload load for LUW 6.1.0.1IF1

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.