Ibm Db2 Universal Database vulnerabilities
66 known vulnerabilities affecting ibm/db2_universal_database.
Total CVEs
66
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH22MEDIUM32LOW3
Vulnerabilities
Page 4 of 4
CVE-2008-3855P4MEDIUMCVSS 4.6v9.12008-08-28
CVE-2008-3855 [MEDIUM] CVE-2008-3855: Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component
Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.
nvd
CVE-2008-3857P4MEDIUMCVSS 4.6v9.12008-08-28
CVE-2008-3857 [MEDIUM] CWE-200 CVE-2008-3857: The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
nvd
CVE-2009-4150P4MEDIUMCVSS 4.6v82009-12-02
CVE-2009-4150 [MEDIUM] CWE-264 CVE-2009-4150: dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits executi
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
nvd
CVE-2003-1049P4MEDIUMCVSS 4.6v7.0v8.02004-09-28
CVE-2003-1049 [MEDIUM] CVE-2003-1049: IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissi
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.
nvd
CVE-2007-4272P4LOWCVSS 1.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4272 [LOW] CVE-2007-4272: Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variabl
nvd
CVE-2007-4271P4LOWCVSS 2.1≤ 8.0≤ 9.12007-08-18
CVE-2007-4271 [LOW] CWE-22 CVE-2007-4271: Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows l
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.
nvd
← Previous4 / 4