Lucene search

K
cveIbmCVE-2017-1150
HistoryMar 08, 2017 - 7:59 p.m.

CVE-2017-1150

2017-03-0819:59:00
CWE-269
ibm
web.nvd.nist.gov
37
ibm
db2
linux
unix
windows
security
vulnerability
cve-2017-1150
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

3.9

Confidence

High

EPSS

0.001

Percentile

27.4%

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

Affected configurations

Nvd
Vulners
Node
ibmdb2Match10.1
OR
ibmdb2Match10.1advanced_enterprise
OR
ibmdb2Match10.1advanced_workgroup
OR
ibmdb2Match10.1enterprise
OR
ibmdb2Match10.1express
OR
ibmdb2Match10.1workgroup
OR
ibmdb2Match10.5
OR
ibmdb2Match10.5advanced_enterprise
OR
ibmdb2Match10.5advanced_workgroup
OR
ibmdb2Match10.5enterprise
OR
ibmdb2Match10.5express
OR
ibmdb2Match10.5workgroup
OR
ibmdb2Match11.1
OR
ibmdb2Match11.1advanced_enterprise
OR
ibmdb2Match11.1advanced_workgroup
OR
ibmdb2Match11.1enterprise
OR
ibmdb2Match11.1express
OR
ibmdb2Match11.1workgroup
VendorProductVersionCPE
ibmdb210.1cpe:2.3:a:ibm:db2:10.1:*:*:*:*:*:*:*
ibmdb210.1cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_enterprise:*:*:*
ibmdb210.1cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_workgroup:*:*:*
ibmdb210.1cpe:2.3:a:ibm:db2:10.1:*:*:*:enterprise:*:*:*
ibmdb210.1cpe:2.3:a:ibm:db2:10.1:*:*:*:express:*:*:*
ibmdb210.1cpe:2.3:a:ibm:db2:10.1:*:*:*:workgroup:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:*:*:*:*:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_enterprise:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_workgroup:*:*:*
ibmdb210.5cpe:2.3:a:ibm:db2:10.5:*:*:*:enterprise:*:*:*
Rows per page:
1-10 of 181

CNA Affected

[
  {
    "product": "DB2 for Linux, UNIX and Windows",
    "vendor": "IBM Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "10.5"
      },
      {
        "status": "affected",
        "version": "10.1"
      },
      {
        "status": "affected",
        "version": "11.1"
      }
    ]
  }
]

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

3.9

Confidence

High

EPSS

0.001

Percentile

27.4%

Related for CVE-2017-1150