CVE-2020-4945

HIGH

IBM Db2 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6466367
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/191945
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210720-0006/

Scores

CVSS v3 8.1
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
ibm/db2 11.5
Published Jun 24, 2021
Tracked Since Feb 18, 2026