← Back

CVE-2020-4976

nvd nist
Published: Mar 11, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.5
Source: NVD

Description

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.

Affected (34)

1 product
Db2
1 product
Oncommand Insight
Configuration A
33 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Ibm
From 11.1.0.0 to 11.1.4.6
From 11.5 to 11.5.5.0
Version 10.1
Version 10.1 fp1
Version 10.1 fp2
Version 10.1 fp3
Version 10.1 fp3a
Version 10.1 fp4
Version 10.1 fp5
Version 10.5
Version 10.5 fp1
Version 10.5 fp2
Version 10.5 fp3
Version 10.5 fp3a
Version 10.5 fp4
Version 10.5 fp5
Version 10.5 fp6
Version 10.5 fp7
Version 10.5 fp8
Version 10.5 fp9
Version 9.7
Version 9.7 fp10
Version 9.7 fp1
Version 9.7 fp2
Version 9.7 fp3
Version 9.7 fp3a
Version 9.7 fp4
Version 9.7 fp5
Version 9.7 fp6
Version 9.7 fp7
Version 9.7 fp8
Version 9.7 fp9
Version 9.7 fp9a
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (6)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.