CVE-2014-0907
Summary
| CVE | CVE-2014-0907 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-30 23:55:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Local escalation of privilege vulnerability in IBM® DB2® (CVE-2014-0907). | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| Security Advisory SA59463 - IBM Data Server Client Privilege Escalation Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA59451 - IBM Tivoli Composite Application Manager for Transactions OpenSSL Security Issue and Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IT00686: SECURITY: ELEVATED PRIVILEGES WITH DB2 EXECUTABLES (CVE-2014-0907) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| Full Disclosure: CVE-2014-0907 - SetUID/SetGID Programs Allow Privilege Escalation Via Insecure RPATH In IBM DB2 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE-2014-0907 - Portcullis | af854a3a-2127-422b-91ae-364da2661108 | www.portcullis-security.com | |
| IT00686: SECURITY: ELEVATED PRIVILEGES WITH DB2 EXECUTABLES (CVE-2014-0907) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Security Advisory SA60482 - IBM Tivoli Storage Manager Client Security Bypass and Privilege Escalation Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Bulletin: IBM Tivoli Composite Application Manager for Transactions is affected by a Local escalation of privilege vulnerability (CVE-2014-0907) | af854a3a-2127-422b-91ae-364da2661108 | www-304.ibm.com | |
| www-01.ibm.com/support/docview.wss | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Security Bulletin: TSM client SetUID elevation of privilege (CVE-2014-0907) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Tivoli Composite Application Manager for Transactions Unsafe Library Loading Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Vulnerabilities, HIPER and Special Attention APARs fixed in DB2 for Linux, UNIX, and Windows Version 10.1 | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| IBM DB2 Privilege Escalation ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| IT00684: SECURITY: ELEVATED PRIVILEGES WITH DB2 EXECUTABLES (CVE-2014-0907) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Multiple IBM DB2 Products CVE-2014-0907 Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Tivoli Composite Application Manager for Transactions Internet Service Monitoring 7.3.0.1 Interim Fix 29 README Tivoli Composite Application Manager for Transactions 7.3.0.1 7.3.0.1-TIV-CAMIS-IF0029 Readme - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IT00687: SECURITY: ELEVATED PRIVILEGES WITH DB2 EXECUTABLES (CVE-2014-0907) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM Tivoli Composite Application Manager for Transactions Internet Service Monitoring 7.4 Interim Fix 13 README Tivoli Composite Application Manager for Transactions 7.4.0.0 7.4.0.0-TIV-CAMIS-IF0013 Readme - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| www-01.ibm.com/support/docview.wss | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM DB2 Unsafe Library Loading Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.