CVE Vulnerabilities

CVE-2016-5995

Published: Oct 01, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.

Affected Software

NameVendorStart VersionEnd Version
Db2Ibm9.7 (including)9.7 (including)
Db2Ibm9.7.0.1 (including)9.7.0.1 (including)
Db2Ibm9.7.0.2 (including)9.7.0.2 (including)
Db2Ibm9.7.0.3 (including)9.7.0.3 (including)
Db2Ibm9.7.0.4 (including)9.7.0.4 (including)
Db2Ibm9.7.0.5 (including)9.7.0.5 (including)
Db2Ibm9.7.0.6 (including)9.7.0.6 (including)
Db2Ibm9.7.0.7 (including)9.7.0.7 (including)
Db2Ibm9.7.0.8 (including)9.7.0.8 (including)
Db2Ibm9.7.0.9 (including)9.7.0.9 (including)
Db2Ibm9.7.0.10 (including)9.7.0.10 (including)
Db2Ibm9.7.0.11 (including)9.7.0.11 (including)
Db2Ibm10.1 (including)10.1 (including)
Db2Ibm10.1.0.1 (including)10.1.0.1 (including)
Db2Ibm10.1.0.2 (including)10.1.0.2 (including)
Db2Ibm10.1.0.3 (including)10.1.0.3 (including)
Db2Ibm10.1.0.4 (including)10.1.0.4 (including)
Db2Ibm10.1.0.5 (including)10.1.0.5 (including)
Db2Ibm10.5 (including)10.5 (including)
Db2Ibm10.5.0.1 (including)10.5.0.1 (including)
Db2Ibm10.5.0.2 (including)10.5.0.2 (including)
Db2Ibm10.5.0.3 (including)10.5.0.3 (including)
Db2Ibm10.5.0.4 (including)10.5.0.4 (including)
Db2Ibm10.5.0.5 (including)10.5.0.5 (including)
Db2Ibm10.5.0.6 (including)10.5.0.6 (including)
Db2Ibm10.5.0.7 (including)10.5.0.7 (including)
Db2Ibm11.1.0.0 (including)11.1.0.0 (including)
Db2_connectIbm9.7 (including)9.7 (including)
Db2_connectIbm9.7.0.1 (including)9.7.0.1 (including)
Db2_connectIbm9.7.0.2 (including)9.7.0.2 (including)
Db2_connectIbm9.7.0.3 (including)9.7.0.3 (including)
Db2_connectIbm9.7.0.4 (including)9.7.0.4 (including)
Db2_connectIbm9.7.0.5 (including)9.7.0.5 (including)
Db2_connectIbm9.7.0.6 (including)9.7.0.6 (including)
Db2_connectIbm9.7.0.7 (including)9.7.0.7 (including)
Db2_connectIbm9.7.0.8 (including)9.7.0.8 (including)
Db2_connectIbm9.7.0.9 (including)9.7.0.9 (including)
Db2_connectIbm9.7.0.10 (including)9.7.0.10 (including)
Db2_connectIbm9.7.0.11 (including)9.7.0.11 (including)
Db2_connectIbm10.1 (including)10.1 (including)
Db2_connectIbm10.1.0.1 (including)10.1.0.1 (including)
Db2_connectIbm10.1.0.2 (including)10.1.0.2 (including)
Db2_connectIbm10.1.0.3 (including)10.1.0.3 (including)
Db2_connectIbm10.1.0.4 (including)10.1.0.4 (including)
Db2_connectIbm10.1.0.5 (including)10.1.0.5 (including)
Db2_connectIbm10.5 (including)10.5 (including)
Db2_connectIbm10.5.0.1 (including)10.5.0.1 (including)
Db2_connectIbm10.5.0.2 (including)10.5.0.2 (including)
Db2_connectIbm10.5.0.3 (including)10.5.0.3 (including)
Db2_connectIbm10.5.0.4 (including)10.5.0.4 (including)
Db2_connectIbm10.5.0.5 (including)10.5.0.5 (including)
Db2_connectIbm10.5.0.6 (including)10.5.0.6 (including)
Db2_connectIbm10.5.0.7 (including)10.5.0.7 (including)
Db2_connectIbm11.1.0.0 (including)11.1.0.0 (including)

References