Impact
IBM Db2 11.5 and 12.1 releases are affected by a stack-based buffer overflow in the setgid helper db2flacc. The overflow can be triggered from an unprivileged shell and can lead to privilege escalation, allowing a local attacker to gain higher privileges and potentially compromise the Db2 instance. The vulnerability is categorized as CWE-121.
Affected Systems
The vulnerable versions are Db2 11.5.0 through 11.5.9 and Db2 12.1.0 through 12.1.4. Affected products are available across IBM:Db2 releases in these version ranges.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity level. The EPSS score of < 1% suggests a low probability of exploitation at this time, though the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers would need local access to trigger the buffer overflow in the setgid helper. If successful, the overflow can lead to privilege escalation and compromise the Db2 instance, allowing the attacker to gain higher privileges.
OpenCVE Enrichment