
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) version 11.5 contains a vulnerability (CVE-2020-4945) that could allow an authenticated user to overwrite arbitrary files due to improper group permissions. The vulnerability was discovered in December 2019 and publicly disclosed in June 2021 (IBM Bulletin).
The vulnerability has a CVSS Base score of 6.5 (MEDIUM) with a vector string of CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. The issue affects all fix pack levels of IBM Db2 V11.5 edition specifically on Linux and Unix platforms, while Windows systems are not impacted (IBM Bulletin).
Successful exploitation of this vulnerability could allow an authenticated user to overwrite arbitrary files on the system due to improper group permissions, potentially leading to system compromise (IBM Bulletin, NetApp Advisory).
IBM has released fixes for this vulnerability in V11.5.6 through APAR IT34964. Users running any vulnerable fixpack level of the affected program V11.5 can download the build containing the fix from Fix Central. The fix can be applied to any affected fixpack level to remediate this vulnerability (IBM Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."