Vulnerability CVE-2018-1710


Published: 2018-09-21

Description:
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> DB2 

 References:
http://www.securityfocus.com/bid/105391
https://exchange.xforce.ibmcloud.com/vulnerabilities/146364
https://usn.ubuntu.com/3906-2/
https://www.ibm.com/support/docview.wss?uid=ibm10729981

Copyright 2024, cxsecurity.com

 

Back to Top