Buffer overflow in IBM DB2 - CVE-2020-4204
Published: June 24, 2022
Vulnerability identifier: #VU64642
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4204
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to execute arbitrary code on the system with root privileges.
The vulnerability exists due to improper bounds checking. A local attacker can trigger the vulnerability and execute arbitrary code on the system with root privileges.
Affected software
IBM DB2
IBM PureData System for Operational Analytics
IBM PureData System for Operational Analytics
How to mitigate CVE-2020-4204
Install updates from vendor's website.
IBM DB2 - addressed in versions 9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1 FP5