Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.811693
Category:Databases
Title:IBM Db2 Multiple Privilege Escalation Vulnerabilities
Summary:IBM DB2 is prone to multiple privilege escalation vulnerabilities.
Description:Summary:
IBM DB2 is prone to multiple privilege escalation vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An unauthorized command that allows the database to be activated when authentication type is CLIENT.

- Multiple errors in validating privileges of local users.

Vulnerability Impact:
Successful exploitation will allow attacker
to obtain root access and a user without proper authority can activate database.

Affected Software/OS:
IBM Db2 versions 9.7 before 9.7 FP11, 10.1 before 10.1 FP6, 10.5 before
10.5 FP8 and 11.1.2.2 before 11.1.2.2 FP2.

Solution:
Apply the appropriate fix from reference links

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-1520
BugTraq ID: 100684
http://www.securityfocus.com/bid/100684
https://exchange.xforce.ibmcloud.com/vulnerabilities/129830
http://www.securitytracker.com/id/1039308
Common Vulnerability Exposure (CVE) ID: CVE-2017-1451
BugTraq ID: 100690
http://www.securityfocus.com/bid/100690
https://exchange.xforce.ibmcloud.com/vulnerabilities/128178
http://www.securitytracker.com/id/1039301
Common Vulnerability Exposure (CVE) ID: CVE-2017-1452
BugTraq ID: 100698
http://www.securityfocus.com/bid/100698
https://exchange.xforce.ibmcloud.com/vulnerabilities/128180
http://www.securitytracker.com/id/1039299
Common Vulnerability Exposure (CVE) ID: CVE-2017-1439
https://exchange.xforce.ibmcloud.com/vulnerabilities/128058
Common Vulnerability Exposure (CVE) ID: CVE-2017-1438
BugTraq ID: 100685
http://www.securityfocus.com/bid/100685
https://exchange.xforce.ibmcloud.com/vulnerabilities/128057
http://www.securitytracker.com/id/1039300
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.