IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6466363 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/190909 | vdb entry vendor advisory |
https://security.netapp.com/advisory/ntap-20210720-0006/ | third party advisory |