CVE Vulnerabilities

CVE-2019-4448

Improper Privilege Management

Published: Aug 26, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authority. IBM X-Force ID: 163489.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Db2_high_performance_unload_loadIbm6.1 (including)6.1 (including)
Db2_high_performance_unload_loadIbm6.1.0.1 (including)6.1.0.1 (including)
Db2_high_performance_unload_loadIbm6.1.0.1-if1 (including)6.1.0.1-if1 (including)
Db2_high_performance_unload_loadIbm6.1.0.1-if2 (including)6.1.0.1-if2 (including)
Db2_high_performance_unload_loadIbm6.1.0.2 (including)6.1.0.2 (including)
Db2_high_performance_unload_loadIbm6.1.0.2-if1 (including)6.1.0.2-if1 (including)

Potential Mitigations

References