IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6456029 | mitigation vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/167365 | vdb entry vendor advisory |
https://security.netapp.com/advisory/ntap-20210629-0004/ | third party advisory |