PT-2005-5529 · Ibm · Ibm Db2

Chris Anley

·

Published

2005-12-31

·

Updated

2024-02-16

·

CVE-2005-4868

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM DB2 version 8.1
Description: The issue allows local users to gain unauthorized access and sensitive information, such as cleartext passwords, due to default permissions of read and write for the Everyone group in shared memory sections and events. This can also cause a denial of service.
Recommendations: For IBM DB2 version 8.1, consider changing the default permissions of shared memory sections and events to restrict access to the Everyone group, limiting it to only necessary users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2005-4868

Affected Products

Ibm Db2