CVE-2020-4701 is a buffer overflow vulnerability in IBM DB2 for Linux, UNIX, and Windows versions 10.5, 11.1, and 11.5, including DB2 Connect Server. This flaw, caused by improper bounds checking, allows a local attacker to execute arbitrary code with root privileges. Rated 7.8 HIGH on CVSS, it presents a significant risk due to its high impact on confidentiality, integrity, and availability, despite requiring local access and low privileges. Currently, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and minimal community discussion or media coverage, indicating it is not actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5CPE matchmatch criteria | cpe:2.3:a:ibm:db2:10.5:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:ibm:db2:11.1:*:*:*:*:*:*:* | ||
11.5CPE matchmatch criteria | cpe:2.3:a:ibm:db2:11.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.