4.4

CVE-2007-1228

IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 8.2
   Unix ≫ Unix
Ibm ≫ Db2 Version 8.2 Update fp1
   Unix ≫ Unix
Ibm ≫ Db2 Version 8.2 Update fp2
   Unix ≫ Unix
Ibm ≫ Db2 Version 8.2 Update fp3
   Unix ≫ Unix
Ibm ≫ Db2 Version 8.2 Update fp4
   Unix ≫ Unix
Ibm ≫ Db2 Version 8.2 Update fp5
   Unix ≫ Unix
Ibm ≫ Db2 Version 8.2 Update fp6
   Unix ≫ Unix
Ibm ≫ Db2 Version 9.0
   Unix ≫ Unix
Ibm ≫ Db2 Version 9.0 Update fp1
   Unix ≫ Unix
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.207
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 2.7 6.9
AV:L/AC:M/Au:S/C:C/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://secunia.com/advisories/24387
Vendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IY86711
Vendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IY87492
Vendor Advisory
http://www.securityfocus.com/bid/22729
http://www.securitytracker.com/id?1017731