Lucene search

K
nvd[email protected]NVD:CVE-2005-4868
HistoryDec 31, 2005 - 5:00 a.m.

CVE-2005-4868

2005-12-3105:00:00
CWE-732
web.nvd.nist.gov
4

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.7%

Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.

Affected configurations

Nvd
Node
ibmdb2_universal_databaseMatch7.1
OR
ibmdb2_universal_databaseMatch7.2
OR
ibmdb2_universal_databaseMatch8.0
OR
ibmdb2_universal_databaseMatch8.1
AND
microsoftwindowsMatch-
VendorProductVersionCPE
ibmdb2_universal_database7.1cpe:2.3:a:ibm:db2_universal_database:7.1:*:*:*:*:*:*:*
ibmdb2_universal_database7.2cpe:2.3:a:ibm:db2_universal_database:7.2:*:*:*:*:*:*:*
ibmdb2_universal_database8.0cpe:2.3:a:ibm:db2_universal_database:8.0:*:*:*:*:*:*:*
ibmdb2_universal_database8.1cpe:2.3:a:ibm:db2_universal_database:8.1:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.7%

Related for NVD:CVE-2005-4868