PublicCVE

CVE-2019-4014

HIGH8.4JSON exportCreate alert

Description

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.

CVSS breakdown

CVSS 3.0
User Interaction
None
Scope
Unchanged
Privileges Required
None
Availability
High
Attack Complexity
Low
Confidentiality
High
Attack Vector
Local
Integrity
High
RL
O
RC
Changed
E
Unchanged

Affected products