IBM Patches Flaws in DB2 Database

執筆者
Brian Prince
Brian Prince
Published: Feb 23, 2007
Updated: Feb 2, 2021
1 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

IBM has patched some serious flaws affecting users of DB2 Universal Database version 9.1 that could be exploited locally by attackers.

A vulnerability in several set-uid DB2 binaries allows a user to write to any file on the system through the use of symbolic links.

In addition, local exploitation of another flaw could allow an attacker to elevate privileges to root.

The flaws were reported to IBM last November, said iDefense researcher Greg MacManus Sr.

“The threat should be fairly limited given that this vulnerability will not allow a remote attacker to access the system; however, if an attacker gained local access they would have no problem getting root,” he said.

According to IBM, there is no workaround for either vulnerability—though the company has issued fixes in DB2 version 9.1 FixPak 2.

The same vulnerabilities exist in DB2 Universal Database Version 8. A fix will be available in DB2 UDB Version 8.1 FixPak 15, which is tentatively scheduled to be released in April, according to a statement posted by IBM. The company urged users to contact DB2 Support if a patch is needed prior to the release of FixPak 15.

Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。