Lucene search

K
cveMitreCVE-2005-4868
HistoryOct 06, 2007 - 9:00 p.m.

CVE-2005-4868

2007-10-0621:00:00
CWE-732
mitre
web.nvd.nist.gov
26
ibm
db2
8.1
shared memory
unauthorized access
sensitive information
denial of service

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.7%

Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.

Affected configurations

Nvd
Node
ibmdb2_universal_databaseMatch7.1
OR
ibmdb2_universal_databaseMatch7.2
OR
ibmdb2_universal_databaseMatch8.0
OR
ibmdb2_universal_databaseMatch8.1
AND
microsoftwindowsMatch-
VendorProductVersionCPE
ibmdb2_universal_database7.1cpe:2.3:a:ibm:db2_universal_database:7.1:*:*:*:*:*:*:*
ibmdb2_universal_database7.2cpe:2.3:a:ibm:db2_universal_database:7.2:*:*:*:*:*:*:*
ibmdb2_universal_database8.0cpe:2.3:a:ibm:db2_universal_database:8.0:*:*:*:*:*:*:*
ibmdb2_universal_database8.1cpe:2.3:a:ibm:db2_universal_database:8.1:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.7%

Related for CVE-2005-4868