VendorsIBMdb2_high_performance_unload_load6.1.0.1
Vulnerabilities

IBM db2 High Performance Unload Load 6.1.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2019-4447
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user controlled location. When a crash is induced the trojan gdb command is executed. IBM X-Force ID: 163488.
Published 2019-08-26 · Modified
8.4EPSS 0.005
CVE-2019-4448
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authority. IBM X-Force ID: 163489.
Published 2019-08-26 · Modified
8.4EPSS 0.003
CVE-2019-4606
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 168298.
Published 2019-12-12 · Modified
7.8EPSS 0.004
CVE-2025-33126
Fixes to common vulnerabilities found in IBM Db2 High Performance Unload
Published 2025-10-27 · Analyzed
6.5EPSS 0.003
CVE-2025-33131
Fixes to common vulnerabilities found in IBM Db2 High Performance Unload
Published 2025-10-27 · Analyzed
6.5EPSS 0.003
CVE-2025-33132
Fixes to common vulnerabilities found in IBM Db2 High Performance Unload
Published 2025-10-27 · Analyzed
6.5EPSS 0.003
CVE-2025-33133
Fixes to common vulnerabilities found in IBM Db2 High Performance Unload
Published 2025-10-27 · Analyzed
6.5EPSS 0.003