Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
References
Link | Resource |
---|---|
http://www-1.ibm.com/support/docview.wss?uid=swg21181228 | Broken Link |
http://www.nextgenss.com/advisories/db205012005F.txt | Not Applicable |
http://www.securityfocus.com/bid/11402 | Broken Link Patch Third Party Advisory VDB Entry |
http://secunia.com/advisories/12733/ | Broken Link Vendor Advisory |
http://marc.info/?l=bugtraq&m=110495402231836&w=2 | Mailing List |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17605 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
History
16 Feb 2024, 14:10
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 7.1 |
References | (SECUNIA) http://secunia.com/advisories/12733/ - Broken Link, Vendor Advisory | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/17605 - Third Party Advisory, VDB Entry | |
References | (MISC) http://www.nextgenss.com/advisories/db205012005F.txt - Not Applicable | |
References | (BID) http://www.securityfocus.com/bid/11402 - Broken Link, Patch, Third Party Advisory, VDB Entry | |
References | (CONFIRM) http://www-1.ibm.com/support/docview.wss?uid=swg21181228 - Broken Link | |
References | (BUGTRAQ) http://marc.info/?l=bugtraq&m=110495402231836&w=2 - Mailing List | |
CPE | cpe:2.3:a:ibm:db2_universal_database:7.1:*:windows:*:*:*:*:* cpe:2.3:a:ibm:db2_universal_database:7.2:*:windows:*:*:*:*:* cpe:2.3:a:ibm:db2_universal_database:8.0:*:windows:*:*:*:*:* |
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:db2_universal_database:8.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:db2_universal_database:7.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:db2_universal_database:8.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:db2_universal_database:7.1:*:*:*:*:*:*:* |
First Time |
Microsoft
Microsoft windows |
|
CWE | CWE-732 |
Information
Published : 2005-12-31 05:00
Updated : 2024-02-16 14:10
NVD link : CVE-2005-4868
Mitre link : CVE-2005-4868
JSON object : View
Products Affected
ibm
- db2_universal_database
microsoft
- windows
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource