Trustwave, which identified the vulnerability and reported it to IBM, says that the issue exists because the developers forgot to include explicit memory protections for the shared memory that the Db2 trace facility uses. A malicious local user could gain read and write access to that memory area, allowing them to access critically sensitive data […]
Latest Comments