[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-4868Date: (C)2005-12-31   (M)2024-02-23


Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.1CVSS Score : 2.1
Exploit Score: 1.8Exploit Score: 3.9
Impact Score: 5.2Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: NONE
Integrity: NONE 
Availability: HIGH 
  
Reference:
BID-11402
SECUNIA-12733
http://marc.info/?l=bugtraq&m=110495402231836&w=2
db2-everyone-gain-access(17605)
http://www-1.ibm.com/support/docview.wss?uid=swg21181228
http://www.nextgenss.com/advisories/db205012005F.txt

CWE    1
CWE-732

© SecPod Technologies