CVE-2014-8910
 
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement.
Vulnerabilidad en IBM DB2 9.7 a través de FP10, 9.8 a través de FP5, 10.1 anterior a FP5 y 10.5 a través de FP5 en Linux, UNIX y Windows permite a usuarios remotos autenticados leer archivos de texto arbitarios a través de una función XML/XSLT en una sentencia SELECT manipulada.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-11-14 CVE Reserved
- 2015-07-20 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/75949 | Vdb Entry | |
http://www.securitytracker.com/id/1032883 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21697988 | 2017-09-22 |
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IT06353 | 2017-09-22 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT06354 | 2017-09-22 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT06355 | 2017-09-22 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT06356 | 2017-09-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7 Search vendor "Ibm" for product "Db2" and version "9.7" | advanced_enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7 Search vendor "Ibm" for product "Db2" and version "9.7" | advanced_workgroup |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7 Search vendor "Ibm" for product "Db2" and version "9.7" | enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7 Search vendor "Ibm" for product "Db2" and version "9.7" | express |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7 Search vendor "Ibm" for product "Db2" and version "9.7" | workgroup |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.8 Search vendor "Ibm" for product "Db2" and version "9.8" | advanced_enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.8 Search vendor "Ibm" for product "Db2" and version "9.8" | advanced_workgroup |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.8 Search vendor "Ibm" for product "Db2" and version "9.8" | enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.8 Search vendor "Ibm" for product "Db2" and version "9.8" | express |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.8 Search vendor "Ibm" for product "Db2" and version "9.8" | workgroup |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.1 Search vendor "Ibm" for product "Db2" and version "10.1" | advanced_enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.1 Search vendor "Ibm" for product "Db2" and version "10.1" | advanced_workgroup |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.1 Search vendor "Ibm" for product "Db2" and version "10.1" | enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.1 Search vendor "Ibm" for product "Db2" and version "10.1" | express |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.1 Search vendor "Ibm" for product "Db2" and version "10.1" | workgroup |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.5 Search vendor "Ibm" for product "Db2" and version "10.5" | advanced_enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.5 Search vendor "Ibm" for product "Db2" and version "10.5" | advanced_workgroup |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.5 Search vendor "Ibm" for product "Db2" and version "10.5" | enterprise |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.5 Search vendor "Ibm" for product "Db2" and version "10.5" | express |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 10.5 Search vendor "Ibm" for product "Db2" and version "10.5" | workgroup |
Affected
|