CVE-2020-4739
20.11.2020, 14:15
IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 188149.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | db2 | 11.5 ≤ 𝑥 < 11.5.5.0 |
ibm | db2 | 9.7.0.0 |
ibm | db2 | 10.1.0.0 |
ibm | db2 | 10.5.0.0 |
ibm | db2 | 11.1.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration