cbcvebase.
CVE-2023-47145
published 2024-01-07

CVE-2023-47145: IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmdb2
ibmdb2>= 10.5 < 10.5.0.1110.5.0.11
ibmdb2>= 11.1 < 11.1.4.711.1.4.7
ibmdb2>= 11.5 < 11.5.811.5.8