CVE-2020-4945
IBM Db2 vulnerability analysis and mitigation

Overview

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) version 11.5 contains a vulnerability (CVE-2020-4945) that could allow an authenticated user to overwrite arbitrary files due to improper group permissions. The vulnerability was discovered in December 2019 and publicly disclosed in June 2021 (IBM Bulletin).

Technical details

The vulnerability has a CVSS Base score of 6.5 (MEDIUM) with a vector string of CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. The issue affects all fix pack levels of IBM Db2 V11.5 edition specifically on Linux and Unix platforms, while Windows systems are not impacted (IBM Bulletin).

Impact

Successful exploitation of this vulnerability could allow an authenticated user to overwrite arbitrary files on the system due to improper group permissions, potentially leading to system compromise (IBM Bulletin, NetApp Advisory).

Exploitability

The vulnerability requires network access and low privilege level for exploitation. An authenticated user could potentially exploit this vulnerability to overwrite arbitrary files on the affected systems (IBM Bulletin).

Mitigation and workarounds

IBM has released fixes for this vulnerability in V11.5.6 through APAR IT34964. Users running any vulnerable fixpack level of the affected program V11.5 can download the build containing the fix from Fix Central. The fix can be applied to any affected fixpack level to remediate this vulnerability (IBM Bulletin).

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10534CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-10543CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-16480HIGH7.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-18097MEDIUM5.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026
CVE-2026-18096LOW3.3
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management