CVE-2019-4101 MEDIUM

CVE-2019-4101

Vendor Ibm
Product DB2 for Linux, UNIX and Windows
Published July 1, 2019
Last update September 16, 2024

CVSS base score

6.2/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.0/UI:N/I:N/AV:L/AC:L/C:N/PR:N/A:H/S:U/E:U/RL:O/RC:C

What the vulnerability does

01Description

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of service. Users that have both EXECUTE on PD_GET_DIAG_HIST and access to the diagnostic directory on the DB2 server can cause the instance to crash. IBM X-Force ID: 158091.

Key dates

02Disclosure timeline

July 1, 2019 CVE published
September 16, 2024 Record updated