Lucene search

K
nvd[email protected]NVD:CVE-2008-3857
HistoryAug 28, 2008 - 5:41 p.m.

CVE-2008-3857

2008-08-2817:41:00
CWE-200
web.nvd.nist.gov
6

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

Low

EPSS

0

Percentile

5.1%

The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.

Affected configurations

Nvd
Node
ibmdb2_universal_databaseMatch9.1aix
OR
ibmdb2_universal_databaseMatch9.1hp_ux
OR
ibmdb2_universal_databaseMatch9.1linux
OR
ibmdb2_universal_databaseMatch9.1solaris
OR
ibmdb2_universal_databaseMatch9.1windows
OR
ibmdb2_universal_databaseMatch9.1fp2aix
OR
ibmdb2_universal_databaseMatch9.1fp2hp-ux
OR
ibmdb2_universal_databaseMatch9.1fp2linux
OR
ibmdb2_universal_databaseMatch9.1fp2solaris
OR
ibmdb2_universal_databaseMatch9.1fp2windows
OR
ibmdb2_universal_databaseMatch9.1fp3aix
OR
ibmdb2_universal_databaseMatch9.1fp3hp-ux
OR
ibmdb2_universal_databaseMatch9.1fp3linux
OR
ibmdb2_universal_databaseMatch9.1fp3solaris
OR
ibmdb2_universal_databaseMatch9.1fp3windows
OR
ibmdb2_universal_databaseMatch9.1fp4hp-ux
OR
ibmdb2_universal_databaseMatch9.1fp4solaris
OR
ibmdb2_universal_databaseMatch9.1fp4windows
OR
ibmdb2_universal_databaseMatch9.1fp4aaix
OR
ibmdb2_universal_databaseMatch9.1fp4ahp-ux
OR
ibmdb2_universal_databaseMatch9.1fp4alinux
OR
ibmdb2_universal_databaseMatch9.1fp4asolaris
OR
ibmdb2_universal_databaseMatch9.1fp4awindows
VendorProductVersionCPE
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:aix:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:hp_ux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:linux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:solaris:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:*:windows:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:aix:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:hp-ux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:linux:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:solaris:*:*:*:*:*
ibmdb2_universal_database9.1cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:windows:*:*:*:*:*
Rows per page:
1-10 of 231

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

Low

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2008-3857