CVE-2020-4204 PUBLISHED CVSS 8.399999618530273 HIGH

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 174960.

EPSS 0.12% · 30.3th percentile

Risk Scores

CVSS v3.0
8.399999618530273
CVSS:3.0/S:U/UI:N/C:H/AC:L/PR:N/A:H/I:H/AV:L/E:U/RL:O/RC:C
EPSS Score
0.12%
30.3th percentile

Affected Products

VendorProductVersions
IBMDB2 for Linux- UNIX and Windows9.7, 10.1, 10.5
ibmdb29.7, 10.1, 10.5

Timeline

References

Open in Interactive Console →