CVE-2011-4061
https://notcve.org/view.php?id=CVE-2011-4061
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header. Múltiples vulnerabilidades de búsqueda no confiable en (1) db2rspgn y (2) kbbacf1 en IBM DB2 Express Edition v9.7, que se utiliza en el IBM Tivoli Monitoring para bases de datos: El agente de DB2, permite a usuarios locales conseguir privilegios a través de un caballo de Troya libkbb.so en el directorio de trabajo actual, en relación con la cabecera ELF DT_RPATH. • http://securityreason.com/securityalert/8476 http://www.nth-dimension.org.uk/downloads.php?id=77 http://www.nth-dimension.org.uk/downloads.php?id=83 http://www.securityfocus.com/archive/1/518659 http://www.securityfocus.com/bid/48514 http://www.securityfocus.com/bid/51181 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14063 •
CVE-2011-1847
https://notcve.org/view.php?id=CVE-2011-1847
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information. IBM DB2 v9.5 anterior a FP7 y v9.7 anterior a FP4 en Linux, UNIX y Windows no fuerzan correctamente los requisitos de privilegios para acceder a la tabla, permitiendo a usuarios remotos autenticados modificar las columnas de estadísticas SYSSTAT.TABLES a través de una instrucción UPDATE. NOTA: algunos de estos detalles han sido obtenidos de información de terceros. • http://secunia.com/advisories/44229 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71413 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC72119 http://www-01.ibm.com/support/docview.wss?uid=swg1IC71413 http://www-01.ibm.com/support/docview.wss?uid=swg1IC72119 http://www.securityfocus.com/bid/47525 http://www.vupen.com/english/advisories/2011/1083 https://exchange.xforce.ibmcloud.com/vulnerabilities/66979 https://oval.cisecurity.org/repository/search/def • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2011-1846
https://notcve.org/view.php?id=CVE-2011-1846
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information. IBM DB2 v9.5 anterior a FP7 y v9.7 anterior a FP4 en Linux, UNIX y Windows no revoca correctamente la pertenencia a grupos, lo que permite a usuarios remotos autenticados ejecutar instrucciones non-DDL aprovechándose de la posesión heredada del rol anterior, una vulnerabilidad diferente de CVE-2011-0757. NOTA: algunos de estos detalles han sido obtenidos de información de terceros. • http://secunia.com/advisories/44229 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375 http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263 http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375 http://www.securityfocus.com/bid/47525 http://www.vupen.com/english/advisories/2011/1083 https://exchange.xforce.ibmcloud.com/vulnerabilities/66980 https://oval.cisecurity.org/repository/search/def • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2011-0757
https://notcve.org/view.php?id=CVE-2011-0757
IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority. IBM DB2 v9.1 anterior a FP10, v9.5 anterior a FP6a, y v9.7 anterior a FP2 en Linux, UNIX y Windows no revoca correctamente la autorización DBADM, que permite a usuarios autenticados remotamente ejecutar instrucciones no-DDL aprovechandose de la posesión anterior de esta autoridad. • http://osvdb.org/70773 http://secunia.com/advisories/43148 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66811 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66814 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66815 http://www.ibm.com/support/docview.wss?uid=swg1IC66811 http://www.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2011-0731
https://notcve.org/view.php?id=CVE-2011-0731
Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors. Desbordamiento de búfer en el componente DB2 Administration Server (DAS) para IBM DB2 v9.1 anterior a FP10, v9.5 anterior a FP7, y v9.7 anterior a FP3 en Linux, UNIX, y Windows permite a atacantes remotos ejecutar código a través de vectores desconocidos • http://secunia.com/advisories/43059 http://www-01.ibm.com/support/docview.wss?uid=swg1IC71203 http://www-01.ibm.com/support/docview.wss?uid=swg1IC72028 http://www-01.ibm.com/support/docview.wss?uid=swg1IC72029 http://www.osvdb.org/70683 http://www.securityfocus.com/bid/46052 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14699 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •