PT-2008-5904 · Ibm · Ibm Db2
Published
2008-10-22
·
Updated
2017-08-08
·
CVE-2008-4693
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.1 before FP6
IBM DB2 versions 9.5 before FP2
Description
The issue allows attackers to obtain sensitive information by reading password-related connection string keyword values from the trace output. This is due to the SORT/LIST SERVICES component in IBM DB2 writing sensitive information to the trace output.
Recommendations
For IBM DB2 version 9.1, update to at least FP6 to resolve the issue.
For IBM DB2 version 9.5, update to at least FP2 to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Db2