Lucene search

K
cveMitreCVE-2007-1228
HistoryMar 02, 2007 - 10:19 p.m.

CVE-2007-1228

2007-03-0222:19:00
CWE-287
mitre
web.nvd.nist.gov
32
2
ibm
db2
udb
unix
security
vulnerability
unauthorized access

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:S/C:C/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

27.4%

IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the “fenced” user to access certain unauthorized directories.

Affected configurations

Nvd
Node
ibmdb2Match8.2
OR
ibmdb2Match8.2fp1
OR
ibmdb2Match8.2fp2
OR
ibmdb2Match8.2fp3
OR
ibmdb2Match8.2fp4
OR
ibmdb2Match8.2fp5
OR
ibmdb2Match8.2fp6
OR
ibmdb2Match9.0
OR
ibmdb2Match9.0fp1
AND
unixunix
VendorProductVersionCPE
ibmdb28.2cpe:2.3:a:ibm:db2:8.2:*:*:*:*:*:*:*
ibmdb28.2cpe:2.3:a:ibm:db2:8.2:fp1:*:*:*:*:*:*
ibmdb28.2cpe:2.3:a:ibm:db2:8.2:fp2:*:*:*:*:*:*
ibmdb28.2cpe:2.3:a:ibm:db2:8.2:fp3:*:*:*:*:*:*
ibmdb28.2cpe:2.3:a:ibm:db2:8.2:fp4:*:*:*:*:*:*
ibmdb28.2cpe:2.3:a:ibm:db2:8.2:fp5:*:*:*:*:*:*
ibmdb28.2cpe:2.3:a:ibm:db2:8.2:fp6:*:*:*:*:*:*
ibmdb29.0cpe:2.3:a:ibm:db2:9.0:*:*:*:*:*:*:*
ibmdb29.0cpe:2.3:a:ibm:db2:9.0:fp1:*:*:*:*:*:*
unixunix*cpe:2.3:o:unix:unix:*:*:*:*:*:*:*:*

Social References

More

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:S/C:C/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

27.4%