CVE-2008-3856
published 2008-08-28CVE-2008-3856: The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.40%
82.1th percentile
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2_universal_database | <= 8 | — |
| ibm | db2_universal_database | <= 9.1 | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg89-rv67-669v: The db2fmp process in IBM DB2 8 before FP17, 9
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2008-6820 [HIGH] GHSA-hg89-rv67-669v: The db2fmp process in IBM DB2 8 before FP17, 9
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
GHSA
GHSA-g8fv-c9gr-q25c: The routine infrastructure component in IBM DB2 8 before FP17, 9
ghsa_unreviewed·2022-05-03
CVE-2008-3856 [HIGH] GHSA-g8fv-c9gr-q25c: The routine infrastructure component in IBM DB2 8 before FP17, 9
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXTftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXThttp://secunia.com/advisories/29784http://secunia.com/advisories/31787http://www-01.ibm.com/support/docview.wss?uid=swg1IZ19155http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20350http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20352http://www-1.ibm.com/support/docview.wss?uid=swg21255607http://www.securityfocus.com/bid/29601http://www.securityfocus.com/bid/31058https://exchange.xforce.ibmcloud.com/vulnerabilities/45140ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXTftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXThttp://secunia.com/advisories/29784http://secunia.com/advisories/31787http://www-01.ibm.com/support/docview.wss?uid=swg1IZ19155http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20350http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20352http://www-1.ibm.com/support/docview.wss?uid=swg21255607http://www.securityfocus.com/bid/29601http://www.securityfocus.com/bid/31058https://exchange.xforce.ibmcloud.com/vulnerabilities/45140
2008-08-28
Published