Description
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.
CVSS breakdown
CVSS 3.0
User Interaction
None
Scope
Unchanged
Privileges Required
None
Availability
High
Attack Complexity
Low
Confidentiality
High
Attack Vector
Local
Integrity
High
RL
O
RC
Changed
E
Unchanged