CVE-2011-4061
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the…
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Affected
- ibm/db2 · ibm/tivoli monitoring for databases
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/8476
- http://www.nth-dimension.org.uk/downloads.php?id=77
- http://www.nth-dimension.org.uk/downloads.php?id=83Exploit
- http://www.securityfocus.com/archive/1/518659
- http://www.securityfocus.com/bid/48514Exploit
- http://www.securityfocus.com/bid/51181
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14063
- http://securityreason.com/securityalert/8476
- http://www.nth-dimension.org.uk/downloads.php?id=77
- http://www.nth-dimension.org.uk/downloads.php?id=83Exploit
- http://www.securityfocus.com/archive/1/518659
- http://www.securityfocus.com/bid/48514Exploit
- http://www.securityfocus.com/bid/51181
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14063
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.