PT-2008-5904 · Ibm · Ibm Db2

Published

2008-10-22

·

Updated

2017-08-08

·

CVE-2008-4693

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM DB2 versions 9.1 before FP6 IBM DB2 versions 9.5 before FP2
Description The issue allows attackers to obtain sensitive information by reading password-related connection string keyword values from the trace output. This is due to the SORT/LIST SERVICES component in IBM DB2 writing sensitive information to the trace output.
Recommendations For IBM DB2 version 9.1, update to at least FP6 to resolve the issue. For IBM DB2 version 9.5, update to at least FP2 to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4693

Affected Products

Ibm Db2