Security features bypass in Db2U - CVE-2023-261257

 

Security features bypass in Db2U - CVE-2023-261257

Published: May 29, 2024


Vulnerability identifier: #VU89868
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-261257
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A local user with access to the kubernetes pod can make system calls compromising the security of containers.


Affected software

Db2U
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data

How to mitigate CVE-2023-261257

Install updates from vendor's website.

DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5

External References

Related Security Bulletins