Lucene search

K
cveIbmCVE-2014-0919
HistoryMay 08, 2015 - 1:59 a.m.

CVE-2014-0919

2015-05-0801:59:00
CWE-200
ibm
web.nvd.nist.gov
296
ibm
db2
linux
unix
windows
passwords
sql
remote authentication
sensitive information
cve-2014-0919
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.002

Percentile

57.6%

IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.

Affected configurations

Nvd
Node
ibmdb2Match9.5advanced_enterprise
OR
ibmdb2Match9.5advanced_workgroup
OR
ibmdb2Match9.5enterprise
OR
ibmdb2Match9.5express
OR
ibmdb2Match9.5workgroup
OR
ibmdb2Match9.7advanced_enterprise
OR
ibmdb2Match9.7advanced_workgroup
OR
ibmdb2Match9.7enterprise
OR
ibmdb2Match9.7express
OR
ibmdb2Match9.7workgroup
OR
ibmdb2Match9.8advanced_enterprise
OR
ibmdb2Match9.8advanced_workgroup
OR
ibmdb2Match9.8enterprise
OR
ibmdb2Match9.8express
OR
ibmdb2Match9.8workgroup
OR
ibmdb2Match10.1advanced_enterprise
OR
ibmdb2Match10.1advanced_workgroup
OR
ibmdb2Match10.1enterprise
OR
ibmdb2Match10.1express
OR
ibmdb2Match10.1workgroup
OR
ibmdb2Match10.5advanced_enterprise
OR
ibmdb2Match10.5advanced_workgroup
OR
ibmdb2Match10.5enterprise
OR
ibmdb2Match10.5express
OR
ibmdb2Match10.5workgroup
VendorProductVersionCPE
ibmdb29.5cpe:2.3:a:ibm:db2:9.5:*:*:*:advanced_enterprise:*:*:*
ibmdb29.5cpe:2.3:a:ibm:db2:9.5:*:*:*:advanced_workgroup:*:*:*
ibmdb29.5cpe:2.3:a:ibm:db2:9.5:*:*:*:enterprise:*:*:*
ibmdb29.5cpe:2.3:a:ibm:db2:9.5:*:*:*:express:*:*:*
ibmdb29.5cpe:2.3:a:ibm:db2:9.5:*:*:*:workgroup:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup:*:*:*
Rows per page:
1-10 of 251

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.002

Percentile

57.6%