CVE Vulnerabilities

CVE-2019-4448

Improper Privilege Management

Published: Aug 26, 2019 | Modified: Dec 02, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authority. IBM X-Force ID: 163489.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Db2_high_performance_unload_load Ibm 6.1 (including) 6.1 (including)
Db2_high_performance_unload_load Ibm 6.1.0.1 (including) 6.1.0.1 (including)
Db2_high_performance_unload_load Ibm 6.1.0.1-if1 (including) 6.1.0.1-if1 (including)
Db2_high_performance_unload_load Ibm 6.1.0.1-if2 (including) 6.1.0.1-if2 (including)
Db2_high_performance_unload_load Ibm 6.1.0.2 (including) 6.1.0.2 (including)
Db2_high_performance_unload_load Ibm 6.1.0.2-if1 (including) 6.1.0.2-if1 (including)

Potential Mitigations

References