Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-1998

Overview

Vulnerability Score 8.5 8.5
CVE Id CVE-2008-1998
Last Modified 30 Oct 2012 10:56:28
Published 28 Apr 2008 04:05:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication SINGLE_INSTANCE

CVE-2008-1998

Summary

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.

Vulnerable Systems

Application

  • Ibm Db2 8.0

  • Ibm Db2 9.1

  • Ibm Db2 9.5


References

BUGTRAQ - 20080418 Team SHATTER Security Advisory: IBM DB2 UDB Arbitrary file overwrite in SYSPROC.NNSTAT procedure

MISC - http://www.appsecinc.com/resources/alerts/db2/2008-03.shtml

AIXAPAR - IZ10776

AIXAPAR - IZ06977

AIXAPAR - IZ06976

SREASON - 3840

SECUNIA - 29784

SECUNIA - 29022

XF - ibm-db2-nnstat-file-overwrite(41960)

BID - 28836


Last Updated: 27 May 2016 10:47:18