Arbitrary Code Execution Vulnerability in IBM DB2 High Performance Unload
CVE-2019-4606
7.4HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 12 December 2019
Summary
A vulnerability exists in IBM DB2 High Performance Unload for LUW 6.1 and 6.5, where a local attacker can exploit an untrusted search path to execute arbitrary code. This can occur when an attacker utilizes a specially crafted executable file, leading to potential system compromise. Organizations using this software should take immediate action to mitigate the risk by applying necessary security updates and evaluating their system’s integrity.
Affected Version(s)
Db2 High Performance Unload load for LUW 6.5
DB2 High Performance Unload load for LUW 6.1
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved