CVE-2008-6820IBM DB2 vulnerability

3 documents3 sources
Severity
10.0CRITICALNVD
CNA7.5
EPSS
0.8%
top 26.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateMay 17

Description

The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDibm/db28.0, 9.1, 9.5+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hg89-rv67-669v: The db2fmp process in IBM DB2 8 before FP17, 92022-05-17
CVEList
CVE-2008-6820: The db2fmp process in IBM DB2 8 before FP17, 92009-06-03
CVE-2008-6820 — IBM DB2 vulnerability | cvebase