CVE-2020-4945
published 2021-06-24CVE-2020-4945: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group…
PriorityP340high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
1.04%
60.2th percentile
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2_for_linux_and_unix | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fhg4-xhw8-92hr: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11
ghsa_unreviewed·2022-05-24
CVE-2020-4945 [HIGH] CWE-732 GHSA-fhg4-xhw8-92hr: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
OSV
linux-raspi, linux-raspi-5.4 vulnerabilities
osv·2021-05-19·CVSS 4.4
linux-raspi, linux-raspi-5.4 vulnerabilities
linux-raspi, linux-raspi-5.4 vulnerabilities
USN-4945-1 fixed vulnerabilities in the Linux kernel for Ubuntu
20.04 LTS and Ubuntu 18.04 LTS. This update provides the corresponding
Linux kernel updates targeted specifically for Raspberry Pi devices
in those same Ubuntu Releases.
Original advisory details:
It was discovered that the Nouveau GPU driver in the Linux kernel did not
properly handle error conditions in some situations. A local attacker could
use this to cause a denial of service (system crash). (CVE-2020-25639)
Jan Beulich discovered that the Xen netback backend in the Linux kernel did
not properly handle certain error conditions under paravirtualization. An
attacker in a guest VM could possibly use this to cause a denial of service
(host domain crash). (CVE-2021-28038)
It w
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://exchange.xforce.ibmcloud.com/vulnerabilities/191945https://security.netapp.com/advisory/ntap-20210720-0006/https://www.ibm.com/support/pages/node/6466367https://exchange.xforce.ibmcloud.com/vulnerabilities/191945https://security.netapp.com/advisory/ntap-20210720-0006/https://www.ibm.com/support/pages/node/6466367
2021-06-24
Published