PT-2017-13893 · Ibm · Ibm Db2
Published
2017-09-12
·
Updated
2017-09-15
·
CVE-2017-1520
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.7, 10.1, 10.5, and 11.1
Description
The issue allows an unauthorized command to activate the database when the authentication type is set to CLIENT.
Recommendations
For IBM DB2 version 9.7, update to a version that includes a fix for this issue.
For IBM DB2 version 10.1, update to a version that includes a fix for this issue.
For IBM DB2 version 10.5, update to a version that includes a fix for this issue.
For IBM DB2 version 11.1, update to a version that includes a fix for this issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Db2