2.1 Secure DB2 Runtime Library

Information

A DB2 software installation will place all executables under the default <DB2PATH>sqllib directory. This directory needs to be secured so it grants only the necessary access to authorized users and administrators.

Solution

For Windows-
1. Connect to the DB2 host
2. Right-click on the NODE000xsqldbdir directory
3. Choose Properties
4. Select the Security tab
5. Select all DB administrator accounts and grant them the Full Control authority
6. Select all other accounts and revoke all privileges other than Read and Execute
For Linux-
1. Connect to the DB2 host
2. Change to the /NODE000x/sqldbdir directory
3. Change the permission level of the directory to this recommended value
OS => chmod -R 755

See Also

https://workbench.cisecurity.org/files/162