CVE-2017-1150Improper Privilege Management in IBM DB2

Severity
3.1LOWNVD
EPSS
0.2%
top 63.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 8
Latest updateMay 13

Description

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages1 packages

NVDibm/db210.1, 10.5, 11.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3q6v-gv39-h4r6: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 102022-05-13
CVEList
CVE-2017-1150: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 102017-03-08

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - 'IOCTL_MOUNTMGR_QUERY_POINTS' Kernel Mountmgr Pool Memory Disclosure2017-06-21
CVE-2017-1150 — Improper Privilege Management in IBM | cvebase