CVE-2018-1459
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based buffer overflow, caused by improper bounds checking which could lead an attacker to execute arbitrary code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based buffer overflow, caused by improper bounds checking which could lead an attacker to execute arbitrary code. IBM X-Force ID: 140210.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- ibm/db2
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22016142Vendor Advisory
- http://www.securitytracker.com/id/1041005Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140210VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22016142Vendor Advisory
- http://www.securitytracker.com/id/1041005Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140210VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.