IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Db2 | Ibm | 9.7 (including) | 9.7 (including) |
Db2 | Ibm | 10.1 (including) | 10.1 (including) |
Db2 | Ibm | 10.5 (including) | 10.5 (including) |
Db2 | Ibm | 11.1 (including) | 11.1 (including) |