Lucene search

K
cveMitreCVE-2008-3855
HistoryAug 28, 2008 - 5:41 p.m.

CVE-2008-3855

2008-08-2817:41:00
CWE-264
mitre
web.nvd.nist.gov
23
cve-2008-3855
ibm
db2
vulnerability
das
file creation
privileges

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%

Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a โ€œFILE CREATION VULNERABILITY.โ€ NOTE: this may be the same as CVE-2007-5664.

Affected configurations

Nvd
Node
ibmdb2_universal_databaseMatch9.1aix
OR
ibmdb2_universal_databaseMatch9.1hp_ux
OR
ibmdb2_universal_databaseMatch9.1linux
OR
ibmdb2_universal_databaseMatch9.1solaris
OR
ibmdb2_universal_databaseMatch9.1windows
OR
ibmdb2_universal_databaseMatch9.1fp2aix
OR
ibmdb2_universal_databaseMatch9.1fp2hp-ux
OR
ibmdb2_universal_databaseMatch9.1fp2linux
OR
ibmdb2_universal_databaseMatch9.1fp2solaris
OR
ibmdb2_universal_databaseMatch9.1fp2windows
OR
ibmdb2_universal_databaseMatch9.1fp3aix
OR
ibmdb2_universal_databaseMatch9.1fp3hp-ux
OR
ibmdb2_universal_databaseMatch9.1fp3linux
OR
ibmdb2_universal_databaseMatch9.1fp3solaris
OR
ibmdb2_universal_databaseMatch9.1fp3windows
OR
ibmdb2_universal_databaseMatch9.1fp4aix
OR
ibmdb2_universal_databaseMatch9.1fp4hp-ux
OR
ibmdb2_universal_databaseMatch9.1fp4linux
OR
ibmdb2_universal_databaseMatch9.1fp4solaris
OR
ibmdb2_universal_databaseMatch9.1fp4windows
OR
ibmdb2_universal_databaseMatch9.1fp4aaix
OR
ibmdb2_universal_databaseMatch9.1fp4ahp-ux
OR
ibmdb2_universal_databaseMatch9.1fp4alinux
OR
ibmdb2_universal_databaseMatch9.1fp4asolaris
OR
ibmdb2_universal_databaseMatch9.1fp4awindows
VendorProductVersionCPE
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:aix:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:hp_ux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:linux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:solaris:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:windows:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:aix:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:hp-ux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:linux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:solaris:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:windows:*:*:*:*:*
Rows per page:
1-10 of 251

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%