Total vulnerabilities in the database
Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.
Software | From | Fixed in |
---|---|---|
ibm / db2_universal_database | 9.0-fixpak_3a | 9.0-fixpak_3a.x |
ibm / db2_universal_database | - | 8.0.x |