LiveActive security incident?Get immediate response
CVE Record

CVE-2018-1936: IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by im...

IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.

HighCVSS 8.4Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2018-1936 is a high-severity IBM DB2/Db2 flaw in a shared library. A local attacker could trigger a stack buffer overflow and potentially run arbitrary code, affecting confidentiality, integrity, and availability of database servers.

Executive priority

Treat this as a high-priority legacy database risk. It is not evidenced as actively exploited here, but successful exploitation could compromise database servers. Prioritize remediation where affected DB2 hosts support sensitive or regulated data.

Technical view

IBM reports improper bounds checking in libdb2e.so.1 for DB2 9.7, 10.1, 10.5, and Db2 11.1. The CVSS 3.0 score is 8.4 with local attack vector, low complexity, no privileges, no user interaction, and high CIA impact.

Likely exposure

Exposure is limited to environments running the listed IBM DB2/Db2 versions, especially hosts where untrusted local users or processes can access the vulnerable library path. The bundle does not identify network-only exploitation.

Exploitation context

The CVE is not listed as KEV, and the CVSS exploit maturity is unproven. The provided sources support arbitrary code execution risk, but do not provide evidence of active exploitation.

Researcher notes

The key constraint is attack vector: CVSS marks AV:L, so validation should focus on affected local installations and local access paths. The source bundle does not include exploit details, CWE classification, or exact fixed build numbers.

Mitigation direction

  • Inventory DB2 9.7, 10.1, 10.5, and Db2 11.1 installations.
  • Review IBM advisory ibm10741481 for official fixed levels and remediation.
  • Apply IBM-provided fixes or supported upgrades where applicable.
  • Restrict local access to database hosts to trusted administrators and services.
  • Use host isolation and monitoring if immediate remediation is not possible.

Validation and detection

  • Confirm installed DB2/Db2 versions on all database hosts.
  • Check whether libdb2e.so.1 exists in affected DB2 installations.
  • Compare installed fix level against IBM advisory guidance.
  • Review local account access on database servers.
  • Check security monitoring for unusual local process activity near DB2 libraries.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2018-1936 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.4 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/PR:N/S:U/A:H/UI:N/I:H/AC:L/C:H/AV:L/RC:C/E:U/RL:O

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.4CVSS 3.0HighCVSS:3.0/PR:N/S:U/A:H/UI:N/I:H/AC:L/C:H/AV:L/RC:C/E:U/RL:O2.55.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

8.4High
CVSS 3.0 vector shape for CVE-2018-1936Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/PR:N/S:U/A:H/UI:N/I:H/AC:L/C:H/AV:L/RC:C/E:U/RL:O

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMDB29.7, 10.1, 10.5Listed
IBMDb211.1Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.