7.3
CVE-2017-1297
- EPSS 1.49%
- Veröffentlicht 27.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Data Server Client Version -
Ibm ≫ Data Server Driver For Odbc And Cli Version -
Ibm ≫ Data Server Driver Package Version -
Ibm ≫ Data Server Runtime Client Version -
Ibm ≫ Db2 Connect Version 9.7 SwEdition application_server
Ibm ≫ Db2 Connect Version 9.7 SwEdition enterprise
Ibm ≫ Db2 Connect Version 9.7 SwEdition unlimited
Ibm ≫ Db2 Connect Version 10.1 SwEdition application_server
Ibm ≫ Db2 Connect Version 10.1 SwEdition enterprise
Ibm ≫ Db2 Connect Version 10.1 SwEdition unlimited
Ibm ≫ Db2 Connect Version 10.5 SwEdition application_server
Ibm ≫ Db2 Connect Version 10.5 SwEdition enterprise
Ibm ≫ Db2 Connect Version 10.5 SwEdition unlimited
Ibm ≫ Db2 Connect Version 11.1.0.0 SwEdition application_server
Ibm ≫ Db2 Connect Version 11.1.0.0 SwEdition enterprise
Ibm ≫ Db2 Connect Version 11.1.0.0 SwEdition unlimited
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.49% | 0.707 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.3 | 1.3 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 4.4 | 3.4 | 6.4 |
AV:L/AC:M/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://www.ibm.com/support/docview.wss?uid=swg22004878
http://www.securityfocus.com/bid/99271
http://www.securitytracker.com/id/1038772
https://exchange.xforce.ibmcloud.com/vulnerabilities/125159
https://www.exploit-db.com/exploits/42260/