Privilege Escalation in IBM DB2 High Performance Unload for LUW
CVE-2019-4448
8.4HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 26 August 2019
Summary
The IBM DB2 High Performance Unload for LUW versions 6.1 and its updates present a vulnerability where the db2hpum and db2hpum_debug binaries are setuid root. This configuration enables a low privileged user to exploit built-in options, allowing them to load arbitrary DB2 libraries within a privileged context. Consequently, this may lead to the execution of arbitrary code with elevated root permissions, posing a significant security risk.
Affected Version(s)
DB2 High Performance Unload load for LUW 6.1
DB2 High Performance Unload load for LUW 6.1.0.1
DB2 High Performance Unload load for LUW 6.1.0.1IF1
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved