CVE-2011-1846
https://notcve.org/view.php?id=CVE-2011-1846
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information. IBM DB2 v9.5 anterior a FP7 y v9.7 anterior a FP4 en Linux, UNIX y Windows no revoca correctamente la pertenencia a grupos, lo que permite a usuarios remotos autenticados ejecutar instrucciones non-DDL aprovechándose de la posesión heredada del rol anterior, una vulnerabilidad diferente de CVE-2011-0757. NOTA: algunos de estos detalles han sido obtenidos de información de terceros. • http://secunia.com/advisories/44229 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375 http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263 http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375 http://www.securityfocus.com/bid/47525 http://www.vupen.com/english/advisories/2011/1083 https://exchange.xforce.ibmcloud.com/vulnerabilities/66980 https://oval.cisecurity.org/repository/search/def • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2011-0757
https://notcve.org/view.php?id=CVE-2011-0757
IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority. IBM DB2 v9.1 anterior a FP10, v9.5 anterior a FP6a, y v9.7 anterior a FP2 en Linux, UNIX y Windows no revoca correctamente la autorización DBADM, que permite a usuarios autenticados remotamente ejecutar instrucciones no-DDL aprovechandose de la posesión anterior de esta autoridad. • http://osvdb.org/70773 http://secunia.com/advisories/43148 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66811 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66814 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66815 http://www.ibm.com/support/docview.wss?uid=swg1IC66811 http://www.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2011-0731
https://notcve.org/view.php?id=CVE-2011-0731
Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors. Desbordamiento de búfer en el componente DB2 Administration Server (DAS) para IBM DB2 v9.1 anterior a FP10, v9.5 anterior a FP7, y v9.7 anterior a FP3 en Linux, UNIX, y Windows permite a atacantes remotos ejecutar código a través de vectores desconocidos • http://secunia.com/advisories/43059 http://www-01.ibm.com/support/docview.wss?uid=swg1IC71203 http://www-01.ibm.com/support/docview.wss?uid=swg1IC72028 http://www-01.ibm.com/support/docview.wss?uid=swg1IC72029 http://www.osvdb.org/70683 http://www.securityfocus.com/bid/46052 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14699 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2010-3734
https://notcve.org/view.php?id=CVE-2010-3734
The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack. El componente Install en IBM DB2 UDB v9.5 anterior a FP6a sobre Linux, UNIX y Windows, tiene una limitación en el número de caracteres en la longitud de una contraseña, lo que facilita a atacantes acceder a través de un ataque de fuerza bruta. • ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT http://www-01.ibm.com/support/docview.wss?uid=swg1IC62856 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14764 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2010-3733
https://notcve.org/view.php?id=CVE-2010-3733
The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file. El componente Utilities en IBM DB2 UDB v9.5 anterior a FP6a emplea permisos de escritura para todo el mundo (world-writable) para el archivo sqllib/cfg/db2sprf, lo que podría permitir a usuarios locales obtener privilegios mediante la modificación de este archivo. • ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68463 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14707 • CWE-264: Permissions, Privileges, and Access Controls •