News: 1598017139

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Shared memory vulnerability in IBM's Db2 database could let nefarious insiders wreak havoc – so get patching

(2020/08/21)


A bug-hunter has uncovered a vulnerability in IBM's popular enterprise database which, if left unpatched, could allow a local user to access data and kick off a denial-of-service attack.

Security firm Trustwave said the shared memory vulnerability in Db2 - [1]CVE-2020-4414 - was similar to the [2]problems found with Cisco's Webex in June ( [3]CVE-2020-3347 ).

According to TrustWave, "Only Db2 for LUW (Linux, Unix, Windows) is affected. Db2 for other platforms like IBM mainframes and z/OS are unaffected."

Martin Rakhmanov, security research manager at Trustwave, said: "Through recent research we've seen the emergence of shared memory vulnerabilities becoming a more common issue."

The Db2 trace facility could allow any local user to gain read and write access to a shared memory area because the developers had not included explicit memory protections around that function, he said. As such, nefarious insiders could exploit the vulnerability.

"This allows accessing critically sensitive data as well as the ability to change how the trace subsystem functions, which could result in a denial of service," Rakhmanov added.

The Db2 trace facility captures a log of control flow information – such as functions and associated parameter values – and is used by Db2 tech support to diagnose database problems.

In his [4]post , Rakhmanov explained that by launching Process Explorer in Windows, for example, users can see there are no permissions guarding shared memory – anyone can read from and write to it. By then enabling Db2 tracing, the users can see what has been written to shared memory. As well as exposing the data, the vulnerability offers the possibility of launching a denial-of-service condition "simply by writing incorrect data over that memory section".

DB2 migration problems caused IBM to resurrect Netezza, according to analyst [5]READ MORE

The vulnerability could potentially affect Db2 editions 9.7, 10.1, 10.5, 11.1, and 11.5. A [6]special build patch was issued by IBM (here) over a month ago, but if you haven't patched, don't delay.

IBM has not responded to The Register 's request for comment, but its own posting said: "Db2 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service."

Needless to say, TrustWave has recommended Db2 users apply the available patch immediately.

Although lacking the limelight of more modern or cloud-native databases, Db2 still has a loyal userbase including Audi, Japan's Mizuho Bank, and Wells Fargo.

In March, Db2 users on IBM Cloud were [7]hit by an outage lasting several hours. Customers running services hosted at its Dallas data centre – including Watson AI, IBM Cloud, and Db2 – were either partially or completely down.

In 2018, Big Blue [8]issued a notice for CVE-2018-1897 , an elevation-of-privilege flaw that, if exploited, could allow a logged-in attacker to execute code and commands as an admin. ®

Get our [9]Tech Resources



[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4414

[2] https://www.theregister.com/2020/06/18/cisco_webex/

[3] https://nvd.nist.gov/vuln/detail/CVE-2020-3347

[4] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/ibm-db2-shared-memory-vulnerability-cve-2020-4414/

[5] https://www.theregister.com/2020/06/05/db2_migration_netezza/

[6] https://www.ibm.com/support/pages/node/6242356

[7] https://www.theregister.com/2020/03/17/ibm_cloud_tuesday_partial_outage/

[8] https://www.theregister.com/2018/11/29/ibm_db2_security_bugs/

[9] https://whitepapers.theregister.com/

DB2 LUW, that is

cschneid

There are two flavors of DB2, the one that runs on IBM Z and the one that runs on Linux, Unix, and Windows (LUW). Last I knew, they did not share a code base, or shared very little. This affects the LUW version. In future I would suggest making that clear in the article. Perhaps even the headline.

Yes, yes, I know IBM is a failure as a company because it's losing money (except for Z) and no one uses Z (except those who trumpet about their third 5-year plan to migrate to whatever is trendy these days) and so on and so forth ad infinitum ad nauseam etc. etc. etc.

The error of youth is to believe that intelligence is a substitute for
experience, while the error of age is to believe experience is a substitute
for intelligence.
-- Lyman Bryson