Description
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.
References (7)
Core 7
Core References
Various Sources x_refsource_misc
http://www.nth-dimension.org.uk/downloads.php?id=77
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/8476
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/518659
Exploit x_refsource_misc
http://www.nth-dimension.org.uk/downloads.php?id=83
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51181
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/48514
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14063
Scores
EPSS
0.0041
EPSS Percentile
33.8%
Details
Status
published
Products (2)
ibm/db2
9.7
ibm/tivoli_monitoring_for_databases
Published
Oct 18, 2011
Tracked Since
Feb 18, 2026