CVE Vulnerabilities

CVE-2007-1228

Improper Authentication

Published: Mar 02, 2007 | Modified: Feb 11, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:S/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the fenced user to access certain unauthorized directories.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Db2 Ibm 8.2 (including) 8.2 (including)
Db2 Ibm 8.2-fp1 (including) 8.2-fp1 (including)
Db2 Ibm 8.2-fp2 (including) 8.2-fp2 (including)
Db2 Ibm 8.2-fp3 (including) 8.2-fp3 (including)
Db2 Ibm 8.2-fp4 (including) 8.2-fp4 (including)
Db2 Ibm 8.2-fp5 (including) 8.2-fp5 (including)
Db2 Ibm 8.2-fp6 (including) 8.2-fp6 (including)
Db2 Ibm 9.0 (including) 9.0 (including)
Db2 Ibm 9.0-fp1 (including) 9.0-fp1 (including)

Potential Mitigations

References