VulnerabilityModified
CVE-2020-4642
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".
MEDIUM 5.5EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- ibm/db2
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/185589VDB Entry, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210129-0009/Third Party Advisory
- https://www.ibm.com/support/pages/node/6391652Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/185589VDB Entry, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210129-0009/Third Party Advisory
- https://www.ibm.com/support/pages/node/6391652Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.