CVE-2018-1710
https://notcve.org/view.php?id=CVE-2018-1710
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364. En IBM DB2 para Linux, UNIX y Windows (incluye DB2 Connect Server) 10.1, 10.5 y 11.1, la herramienta db2licm se ve afectada por una vulnerabilidad de desbordamiento de búfer que podría resultar en la ejecución de código arbitrario. IBM X-Force ID: 146364. • http://www.securityfocus.com/bid/105391 https://exchange.xforce.ibmcloud.com/vulnerabilities/146364 https://usn.ubuntu.com/3906-2 https://www.ibm.com/support/docview.wss?uid=ibm10729981 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-1711
https://notcve.org/view.php?id=CVE-2018-1711
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369. IBM DB2 para Linux, UNIX y Windows (incluye DB2 Connect Server) 9.7, 10.1, 10.5 y 11.1 podría permitir a un usuario local obtener privilegios debido a que se permite la modificación de columnas en tareas existentes. IBM X-Force ID: 146369. • http://www.securityfocus.com/bid/105390 http://www.securitytracker.com/id/1042175 https://exchange.xforce.ibmcloud.com/vulnerabilities/146369 https://www.ibm.com/support/docview.wss?uid=ibm10729983 • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2018-1487
https://notcve.org/view.php?id=CVE-2018-1487
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972. Los binarios IBM DB2 para Linux, UNIX y Windows (incluye DB2 Connect Server) 9.7, 10.1, 10.5 y 11.1 cargan bibliotecas compartidas de una ruta no fiable que puede otorgar a usuarios con pocos privilegios acceso total a la cuenta de la instancia DB2 mediante la carga de una biblioteca compartida maliciosa. IBM X-Force ID: 140972. • http://www.ibm.com/support/docview.wss?uid=swg22016505 http://www.securitytracker.com/id/1041231 https://exchange.xforce.ibmcloud.com/vulnerabilities/140972 • CWE-426: Untrusted Search Path •
CVE-2018-1458
https://notcve.org/view.php?id=CVE-2018-1458
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209. IBM DB2 para Linux, UNIX y Windows 9.7, 10.1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local ejecutar código arbitrario y llevar a cabo ataques de secuestro de DLL. IBM X-Force ID: 140209. • http://www.securitytracker.com/id/1041230 https://exchange.xforce.ibmcloud.com/vulnerabilities/140209 https://www.ibm.com/support/docview.wss?uid=swg22016624 • CWE-426: Untrusted Search Path •
CVE-2018-1566
https://notcve.org/view.php?id=CVE-2018-1566
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023. IBM DB2 para Linux, UNIX y Windows 9.7, 10.1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local ejecutar código arbitrario debido a un error de cadena de formato. IBM X-Force ID: 143023. • http://www.ibm.com/support/docview.wss?uid=swg22016182 http://www.securityfocus.com/bid/104740 http://www.securitytracker.com/id/1041229 https://exchange.xforce.ibmcloud.com/vulnerabilities/143023 • CWE-134: Use of Externally-Controlled Format String •