IBM Db2
cpe:2.3:a:ibm:db2:*:*:*:*:linux:*:*
- >= 11.5.0, <= 11.5.9
- 11.1
- 10.5
- 10.1
- 9.7
A local privilege escalation vulnerability has been identified in IBM Db2 for Linux, UNIX, and Windows, specifically in versions 11.5.0 through 11.5.9, including Db2 Connect Server. This vulnerability could allow an instance owner to execute malicious code that escalates privileges to root. The issue arises from the execution of unnecessary privileges at a level higher than required, potentially enabling unauthorized access to critical system resources.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain root access on the system.
Users can download a special build containing the interim fix for this vulnerability from Fix Central. This special build is available for version 11.5.9 and can be applied to any affected level of the 11.5 release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.