8.8
CVE-2023-42005
- EPSS 0.29%
- Veröffentlicht 29.05.2024 13:15:48
- Zuletzt bearbeitet 18.08.2025 15:03:51
- Erkennungen
IBM Db2 on Cloud Pak for Data privilege escalation
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Warehouse Version 3.5 Update -
Ibm ≫ Db2 Warehouse Version 3.5 Update refresh_10
Ibm ≫ Db2 Warehouse Version 4.0 Update -
Ibm ≫ Db2 Warehouse Version 4.0 Update refresh_9
Ibm ≫ Db2 Warehouse Version 4.5 Update -
Ibm ≫ Db2 Warehouse Version 4.5 Update refresh_3
Ibm ≫ Db2 Warehouse Version 4.6 Update -
Ibm ≫ Db2 Warehouse Version 4.6 Update refresh_6
Ibm ≫ Db2 Warehouse Version 4.7 Update -
Ibm ≫ Db2 Warehouse Version 4.7 Update refresh_4
Ibm ≫ Db2 Warehouse Version 4.8 Update -
Ibm ≫ Db2 Warehouse Version 4.8 Update refresh_4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.202 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| IBM | 7.4 | 1.4 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://exchange.xforce.ibmcloud.com/vulnerabilities/265264
https://www.ibm.com/support/pages/node/7155078