CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
82.7%
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp2:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp2a:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp3:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp3a:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp4:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp4a:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp5:*:*:*:*:*:* |
ibm | db2 | 9.1 | cpe:2.3:a:ibm:db2:9.1:fp6:*:*:*:*:*:* |
ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
secunia.com/advisories/41218
www-01.ibm.com/support/docview.wss?uid=swg1IC65749
www-01.ibm.com/support/docview.wss?uid=swg1IC65756
www-01.ibm.com/support/docview.wss?uid=swg1IC65762
www-01.ibm.com/support/docview.wss?uid=swg21426108
www-01.ibm.com/support/docview.wss?uid=swg21432298
www.vupen.com/english/advisories/2010/2225
exchange.xforce.ibmcloud.com/vulnerabilities/61445
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13841