Vulnerability CVE-2013-3475


Published: 2013-06-04   Modified: 2013-06-05

Description:
Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
IBM -> DB2 
IBM -> Db2 connect 
IBM -> Smart analytics system 7600 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg1IC92463
http://www-01.ibm.com/support/docview.wss?uid=swg1IC92495
http://www-01.ibm.com/support/docview.wss?uid=swg1IC92496
http://www-01.ibm.com/support/docview.wss?uid=swg1IC92498
http://www-01.ibm.com/support/docview.wss?uid=swg21639194
http://www-01.ibm.com/support/docview.wss?uid=swg21639355
http://www.securityfocus.com/bid/60255
https://exchange.xforce.ibmcloud.com/vulnerabilities/84358

Copyright 2024, cxsecurity.com

 

Back to Top