CVE-2017-1452
https://notcve.org/view.php?id=CVE-2017-1452
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180. IBM DB2 para Linux, UNIX y Windows 9.7, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local obtener privilegios elevados y sobrescribir archivos DB2.. IBM X-Force ID: 128180. • http://www.ibm.com/support/docview.wss?uid=swg22006109 http://www.securityfocus.com/bid/100698 http://www.securitytracker.com/id/1039299 https://exchange.xforce.ibmcloud.com/vulnerabilities/128180 •
CVE-2017-1520
https://notcve.org/view.php?id=CVE-2017-1520
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830. IBM DB2 9.7, 10,1, 10.5 y 11.1 es vulnerable a que se ejecute un comando no autorizado que permita activar la base de datos cuando la autenticación es de tipo CLIENT. IBM X-Force ID: 129830. • http://www.ibm.com/support/docview.wss?uid=swg22007186 http://www.securityfocus.com/bid/100684 http://www.securitytracker.com/id/1039308 https://exchange.xforce.ibmcloud.com/vulnerabilities/129830 • CWE-287: Improper Authentication •
CVE-2017-1105
https://notcve.org/view.php?id=CVE-2017-1105
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668. IBM DB2 para Linux, UNIX y Windows 9.2, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) es vulnerable a un desbordamiento de búfer que podría permitir que un usuario local sobrescriba archivos DB2 o provoque una denegación de servicio (DoS). IBM X-Force ID: 120668. • http://www.ibm.com/support/docview.wss?uid=swg22003877 http://www.securityfocus.com/bid/99264 http://www.securitytracker.com/id/1038773 https://exchange.xforce.ibmcloud.com/vulnerabilities/120668 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-1297 – IBM DB2 9.7/10.1/10.5/11.1 - Command Line Processor Buffer Overflow
https://notcve.org/view.php?id=CVE-2017-1297
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159. IBM DB2 para Linux, Unix y Windows 9.2, 10.1, 10.5 y 11.1 (incluido DB2 Connect Server) es vulnerable a un buffer overflow basado en pila --stack-- causado por una inapropiada verificación de límites lo que podría permitir a un atacante local ejecutar código aleatorio. IBM DB2 versions 9.7, 10.1, 10.5, and 11.1 suffer from a command line process buffer overflow vulnerability. • https://www.exploit-db.com/exploits/42260 http://www.ibm.com/support/docview.wss?uid=swg22004878 http://www.securityfocus.com/bid/99271 http://www.securitytracker.com/id/1038772 https://exchange.xforce.ibmcloud.com/vulnerabilities/125159 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-1150
https://notcve.org/view.php?id=CVE-2017-1150
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515. IBM DB2 para Linux, UNIX y Windows (incluye DB2 Connect Server) 10.1, 10.5 y 11.1 podría permitir a un atacante autenticado con acceso especializado a tablas que no se debería permitir ver. Referencia IBM #: 1999515. • http://www.ibm.com/support/docview.wss?uid=swg21999515 http://www.securityfocus.com/bid/96597 http://www.securitytracker.com/id/1037946 • CWE-269: Improper Privilege Management •