Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2003-1052IBM DB2 vulnerability

5 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.4%
top 40.96%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedSep 28
Latest updateApr 29

Description

IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

NVDibm/db29.0
NVDibm/db2_universal_database7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hvc8-756p-3cpj: IBM DB2 72022-04-29
CVEList
CVE-2003-1052: IBM DB2 72004-08-20

💥Exploits & PoCs

2
Exploit-DB
IBM DB2 - Shared Library Injection2003-08-05
Exploit-DB
Microsoft IIS 5.0 - WebDAV Remote Code Execution (3) (xwdav)2003-07-08
CVE-2003-1052 — IBM DB2 vulnerability | cvebase