CVE-2017-1150
Summary
| CVE | CVE-2017-1150 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-08 19:59:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515. |
Risk And Classification
Primary CVSS: v3.0 3.1 LOW from [email protected]
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Problem Types: CWE-269 | Obtain Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 3.1 | LOW | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 11.1 | All | All | All |
| Application | Ibm | Db2 | 11.1 | All | All | All |
| Application | Ibm | Db2 | 11.1 | All | All | All |
| Application | Ibm | Db2 | 11.1 | All | All | All |
| Application | Ibm | Db2 | 11.1 | All | All | All |
| Application | Ibm | Db2 | 11.1 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM Corporation | DB2 For Linux UNIX And Windows | affected 10.5 | Not specified |
| CNA | IBM Corporation | DB2 For Linux UNIX And Windows | affected 10.1 | Not specified |
| CNA | IBM Corporation | DB2 For Linux UNIX And Windows | affected 11.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Information Disclosure vulnerability affects IBM® DB2® LUW (CVE-2017-1150) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Patch, Vendor Advisory |
| www.securityfocus.com/bid/96597 | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM DB2 Remote Authenticated Users Bypass Table Access Controls in Certain Cases - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.