db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Db2_universal_database | Ibm | 8 (including) | 8 (including) |
Db2_universal_database | Ibm | 9.1 (including) | 9.1 (including) |
Db2_universal_database | Ibm | 9.5 (including) | 9.5 (including) |