CVE-2020-4885Link Following in IBM DB2 FOR Linux AND Unix

CWE-59Link Following4 documents4 sources
Severity
4.7MEDIUMNVD
EPSS
0.1%
top 75.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateMay 24

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages2 packages

NVDibm/db211.5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2mm4-wmfr-3ffm: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 112022-05-24
CVEList
CVE-2020-4885: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 112021-06-24

💬Community

1
Bugzilla
CVE-2020-8624 bind: incorrect enforcement of update-policy rules of type "subdomain"2020-08-18
CVE-2020-4885 — Link Following in IBM | cvebase