DB2 - Problembeschreibung
Problem IC79274 | Status: Geschlossen |
SECURITY: DB2 ESCALATION OF PRIVILEGE VULNERABILITY (CVE-2011-4061) | |
Produkt: | |
DB2 FOR LUW / DB2FORLUW / 970 - DB2 | |
Problembeschreibung: | |
DB2 Server products bundle IBM Tivoli Monitoring Agent (ITMA) which is intended for users of Optim Database Administrator. Use of the Monitoring Agent for DB2 is specifically restricted to supplying monitoring information to the Optim Database Administrator Health and Availability monitoring feature only. There is a vulnerability in ITMA which a local user can exploit to gain escalated privilege. The vulnerability does not exist on DB2 for Windows. | |
Problem-Zusammenfassung: | |
**************************************************************** * USERS AFFECTED: * * DB2 9.7 running on UNIX or LINUX * **************************************************************** * PROBLEM DESCRIPTION: * * See Error Description * **************************************************************** * RECOMMENDATION: * * The fix can be obtained by upgrading to DB2 9.7 Fix Pack 6 * **************************************************************** | |
Local-Fix: | |
ITMA is installed by default. However, ITMA is not required if you are not using Optim Database Administrator to monitor DB2. The vulnerability may be mitigated by uninstalling ITMA. The uninstall information can be found here: V9.7: http://publib.boulder.ibm.com/infocenter/db2luw/v9r7/index.jsp?t opic=/com.ibm.db2.luw.qb.server.doc/doc/t0054822.html The vulnerability may be mitigated by uninstalling ITMA. The uninstall information can be found here: V9.7: http://publib.boulder.ibm.com/infocenter/db2luw/v9r7/index.jsp?t opic=/com.ibm.db2.luw.qb.server.doc/doc/t0054822.html V9.5: http://publib.boulder.ibm.com/infocenter/db2luw/v9r5/index.jsp?t opic=/com.ibm.db2.luw.qb.server.doc/doc/t0054822.html | |
verfügbare FixPacks: | |
DB2 Version 9.7 Fix Pack 6 for Linux, UNIX, and Windows | |
Lösung | |
DB2 9.7 Fix Pack 6 | |
Workaround | |
See Local Fix | |
Bug-Verfolgung | |
Vorgänger : APAR is sysrouted TO one or more of the following: IC79970 Nachfolger : | |
Weitere Daten | |
Datum - Problem gemeldet : Datum - Problem geschlossen : Datum - der letzten Änderung: | 18.10.2011 05.06.2012 11.06.2012 |
Problem behoben ab folgender Versionen (IBM BugInfos) | |
9.7.FP6 | |
Problem behoben lt. FixList in der Version | |
9.7.0.6 |