PT-2017-13893 · Ibm · Ibm Db2

Published

2017-09-12

·

Updated

2017-09-15

·

CVE-2017-1520

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM DB2 versions 9.7, 10.1, 10.5, and 11.1
Description The issue allows an unauthorized command to activate the database when the authentication type is set to CLIENT.
Recommendations For IBM DB2 version 9.7, update to a version that includes a fix for this issue. For IBM DB2 version 10.1, update to a version that includes a fix for this issue. For IBM DB2 version 10.5, update to a version that includes a fix for this issue. For IBM DB2 version 11.1, update to a version that includes a fix for this issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1520

Affected Products

Ibm Db2