IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Db2_universal_database | Ibm | * | 8.0 (including) |
Db2_universal_database | Ibm | 7.1 (including) | 7.1 (including) |