8.5

CVE-2008-1998

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 8.0 Update fp1
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp10
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp11
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp12
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp13
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp14
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp15
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp2
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp3
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp4
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp5
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp6
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp6a
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp6b
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp6c
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp7
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp7a
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp7b
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp8
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp8a
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp9
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 8.0 Update fp9a
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 9.1 Update fp1
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 9.1 Update fp2
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 9.1 Update fp3
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 9.1 Update fp3a
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 9.1 Update fp4
   Microsoft ≫ Windows
Ibm ≫ Db2 Version 9.5
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.5% 0.826
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/29022
Third Party Advisory
http://secunia.com/advisories/29784
Third Party Advisory
http://securityreason.com/securityalert/3840
Third Party Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06976
Vendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06977
Vendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10776
Vendor Advisory
http://www.appsecinc.com/resources/alerts/db2/2008-03.shtml
Third Party Advisory
http://www.securityfocus.com/archive/1/491073/100/0/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/28836
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41960
Third Party Advisory
VDB Entry