Lucene search

K
cveIbmCVE-2015-1922
HistoryJul 20, 2015 - 1:59 a.m.

CVE-2015-1922

2015-07-2001:59:05
CWE-284
ibm
web.nvd.nist.gov
42
ibm
db2
data movement
remote access
authentication
vulnerability
cve-2015-1922

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

53.4%

The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors.

Affected configurations

Nvd
Node
ibmdb2Match9.7advanced_enterprise
OR
ibmdb2Match9.7advanced_workgroup
OR
ibmdb2Match9.7enterprise
OR
ibmdb2Match9.7express
OR
ibmdb2Match9.7workgroup
OR
ibmdb2Match9.8advanced_enterprise
OR
ibmdb2Match9.8advanced_workgroup
OR
ibmdb2Match9.8enterprise
OR
ibmdb2Match9.8express
OR
ibmdb2Match9.8workgroup
OR
ibmdb2Match10.1advanced_enterprise
OR
ibmdb2Match10.1advanced_workgroup
OR
ibmdb2Match10.1enterprise
OR
ibmdb2Match10.1express
OR
ibmdb2Match10.1workgroup
OR
ibmdb2Match10.5advanced_enterprise
OR
ibmdb2Match10.5advanced_workgroup
OR
ibmdb2Match10.5enterprise
OR
ibmdb2Match10.5express
OR
ibmdb2Match10.5workgroup
VendorProductVersionCPE
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup:*:*:*
ibmdb29.8cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_enterprise:*:*:*
ibmdb29.8cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_workgroup:*:*:*
ibmdb29.8cpe:2.3:a:ibm:db2:9.8:*:*:*:enterprise:*:*:*
ibmdb29.8cpe:2.3:a:ibm:db2:9.8:*:*:*:express:*:*:*
ibmdb29.8cpe:2.3:a:ibm:db2:9.8:*:*:*:workgroup:*:*:*
Rows per page:
1-10 of 201

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

53.4%