CVE-2017-1520

Severity
3.7LOW
EPSS
0.2%
top 58.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 12
Latest updateMay 17

Description

IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages2 packages

NVDibm/db227 versions+26
NVDibm/db2_connect27 versions+26

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6rf4-w9fv-4378: IBM DB2 92022-05-17
CVEList
CVE-2017-1520: IBM DB2 92017-09-12

💥Exploits & PoCs

1
Exploit-DB
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free2019-01-25
CVE-2017-1520 (LOW CVSS 3.7) | IBM DB2 9.7 | cvebase.io