[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Security vulnerability in the Engine Utilities component in IBM DB2 UDB 9.5 before FP6a

ID: oval:org.secpod.oval:def:646Date: (C)2011-04-08   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The host is installed with IBM DB2 UDB 9.5 before FP6a and is prone to security vulnerability. A flaw is present in engine utilities component in IBM DB2 which fails to properly handle world-writable permissions for the sqllib/cfg/db2sprf file. Successful exploitation allow local users to gain privileges by modifying this file.

Platform:
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product:
IBM DB2
Reference:
CVE-2010-3733
CVE    1
CVE-2010-3733
CPE    2
cpe:/a:ibm:db2
cpe:/a:ibm:db2:9.5

© SecPod Technologies