PT-2005-5529 · Ibm · Ibm Db2
Chris Anley
·
Published
2005-12-31
·
Updated
2024-02-16
·
CVE-2005-4868
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM DB2 version 8.1
Description:
The issue allows local users to gain unauthorized access and sensitive information, such as cleartext passwords, due to default permissions of read and write for the Everyone group in shared memory sections and events. This can also cause a denial of service.
Recommendations:
For IBM DB2 version 8.1, consider changing the default permissions of shared memory sections and events to restrict access to the Everyone group, limiting it to only necessary users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Db2