CVE-2017-1434
https://notcve.org/view.php?id=CVE-2017-1434
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user. IBM DB2 para Linux, UNIX y Windows 11.1 (incluye DB2 Connect Server), bajo circunstancias no habituales, podría exponer información altamente sensible a un usuario local mediante el registro de errores. • http://www.ibm.com/support/docview.wss?uid=swg22005740 http://www.securityfocus.com/bid/100693 http://www.securitytracker.com/id/1039297 https://exchange.xforce.ibmcloud.com/vulnerabilities/127806 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1451
https://notcve.org/view.php?id=CVE-2017-1451
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178. IBM DB2 para Linux, UNIX y Windows 9.7, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local con privilegios de propietario en la instancia DB2 obtener acceso root. IBM X-Force ID: 128178. • http://www.ibm.com/support/docview.wss?uid=swg22006061 http://www.securityfocus.com/bid/100690 http://www.securitytracker.com/id/1039301 https://exchange.xforce.ibmcloud.com/vulnerabilities/128178 •
CVE-2017-1452
https://notcve.org/view.php?id=CVE-2017-1452
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180. IBM DB2 para Linux, UNIX y Windows 9.7, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local obtener privilegios elevados y sobrescribir archivos DB2.. IBM X-Force ID: 128180. • http://www.ibm.com/support/docview.wss?uid=swg22006109 http://www.securityfocus.com/bid/100698 http://www.securitytracker.com/id/1039299 https://exchange.xforce.ibmcloud.com/vulnerabilities/128180 •
CVE-2017-1520
https://notcve.org/view.php?id=CVE-2017-1520
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830. IBM DB2 9.7, 10,1, 10.5 y 11.1 es vulnerable a que se ejecute un comando no autorizado que permita activar la base de datos cuando la autenticación es de tipo CLIENT. IBM X-Force ID: 129830. • http://www.ibm.com/support/docview.wss?uid=swg22007186 http://www.securityfocus.com/bid/100684 http://www.securitytracker.com/id/1039308 https://exchange.xforce.ibmcloud.com/vulnerabilities/129830 • CWE-287: Improper Authentication •
CVE-2017-1105
https://notcve.org/view.php?id=CVE-2017-1105
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668. IBM DB2 para Linux, UNIX y Windows 9.2, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) es vulnerable a un desbordamiento de búfer que podría permitir que un usuario local sobrescriba archivos DB2 o provoque una denegación de servicio (DoS). IBM X-Force ID: 120668. • http://www.ibm.com/support/docview.wss?uid=swg22003877 http://www.securityfocus.com/bid/99264 http://www.securitytracker.com/id/1038773 https://exchange.xforce.ibmcloud.com/vulnerabilities/120668 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •