Latest versionsfixlist
11.1.0.7 FixList
10.5.0.9 FixList
10.1.0.6 FixList
9.8.0.5 FixList
9.7.0.11 FixList
9.5.0.10 FixList
9.1.0.12 FixList
Have problems? - contact us.
Register for free anmeldung-x26
Contact form kontakt-x26

DB2 - Problem description

Problem IT00686 Status: Closed

SECURITY: ELEVATED PRIVILEGES WITH DB2 EXECUTABLES (CVE-2014-0907)

product:
DB2 FOR LUW / DB2FORLUW / A10 - DB2
Problem description:
There is a vulnerability in several DB2 executables which a 
local user can exploit to gain elevated privilege. 
 
This vulnerability does not exist on DB2 for Windows. 
 
See security bulletin for details: 
http://www.ibm.com/support/docview.wss?uid=swg21672100
Problem Summary:
**************************************************************** 
* USERS AFFECTED:                                              * 
* All DB2 systems on all Linux and Unix platforms at service   * 
* levels from Version 10.1 GA through to Version 10.1 Fix Pack * 
* 3.                                                           * 
**************************************************************** 
* PROBLEM DESCRIPTION:                                         * 
* See Error Description                                        * 
**************************************************************** 
* RECOMMENDATION:                                              * 
* See security                                                 * 
* bulletin:http://www.ibm.com/support/docview.wss?uid=swg21672 * 
* 100                                                          * 
****************************************************************
Local Fix:
available fix packs:
DB2 Version 10.1 Fix Pack 4 for Linux, UNIX, and Windows
DB2 Version 10.1 Fix Pack 3a for Linux, UNIX, and Windows
DB2 Version 10.1 Fix Pack 6 for Linux, UNIX, and Windows

Solution
See security bulletin: 
http://www.ibm.com/support/docview.wss?uid=swg21672100
Workaround
not known / see Local fix
Timestamps
Date  - problem reported    :
Date  - problem closed      :
Date  - last modified       :
28.03.2014
25.05.2014
06.06.2014
Problem solved at the following versions (IBM BugInfos)
Problem solved according to the fixlist(s) of the following version(s)
10.1.0.4 FixList