IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg22012896 | vendor advisory |
http://www.securitytracker.com/id/1041227 | vdb entry |
http://www.securityfocus.com/bid/103422 | third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/133999 | vdb entry vendor advisory |