IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2019-03-19T13:50:17.326534Z
Updated: 2024-09-17T02:42:48.476Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-4094
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-21T16:01:05.217
Modified: 2024-11-21T04:43:10.363
Link: CVE-2019-4094
Redhat
No data.