8.8
CVE-2023-42005
- EPSS 0.12%
- Veröffentlicht 29.05.2024 13:15:48
- Zuletzt bearbeitet 18.08.2025 15:03:51
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Db2 on Cloud Pak for Data privilege escalation
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Warehouse Version3.5 Update-
Ibm ≫ Db2 Warehouse Version3.5 Updaterefresh_10
Ibm ≫ Db2 Warehouse Version4.0 Update-
Ibm ≫ Db2 Warehouse Version4.0 Updaterefresh_9
Ibm ≫ Db2 Warehouse Version4.5 Update-
Ibm ≫ Db2 Warehouse Version4.5 Updaterefresh_3
Ibm ≫ Db2 Warehouse Version4.6 Update-
Ibm ≫ Db2 Warehouse Version4.6 Updaterefresh_6
Ibm ≫ Db2 Warehouse Version4.7 Update-
Ibm ≫ Db2 Warehouse Version4.7 Updaterefresh_4
Ibm ≫ Db2 Warehouse Version4.8 Update-
Ibm ≫ Db2 Warehouse Version4.8 Updaterefresh_4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.315 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@us.ibm.com | 7.4 | 1.4 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|