CVE-2007-4271

CWE-22Path Traversal3 documents3 sources
Severity
2.1LOW
EPSS
0.1%
top 82.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 18
Latest updateMay 1

Description

Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-542j-f8v7-ww99: Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 92022-05-01
CVEList
CVE-2007-4271: Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 92007-08-18
CVE-2007-4271 (LOW CVSS 2.1) | Directory traversal vulnerability i | cvebase.io