Privilege Escalation in IBM DB2 High Performance Unload for LUW
CVE-2019-4448

8.4HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 August 2019

Summary

The IBM DB2 High Performance Unload for LUW versions 6.1 and its updates present a vulnerability where the db2hpum and db2hpum_debug binaries are setuid root. This configuration enables a low privileged user to exploit built-in options, allowing them to load arbitrary DB2 libraries within a privileged context. Consequently, this may lead to the execution of arbitrary code with elevated root permissions, posing a significant security risk.

Affected Version(s)

DB2 High Performance Unload load for LUW 6.1

DB2 High Performance Unload load for LUW 6.1.0.1

DB2 High Performance Unload load for LUW 6.1.0.1IF1

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.