PT-2008-5904 · Ibm · Ibm Db2
Publicado
2008-10-22
·
Atualizado
2017-08-08
·
CVE-2008-4693
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.1 before FP6
IBM DB2 versions 9.5 before FP2
Description
The issue allows attackers to obtain sensitive information by reading password-related connection string keyword values from the trace output. This is due to the SORT/LIST SERVICES component in IBM DB2 writing sensitive information to the trace output.
Recommendations
For IBM DB2 version 9.1, update to at least FP6 to resolve the issue.
For IBM DB2 version 9.5, update to at least FP2 to resolve the issue.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Db2