IBM DB2 Universal Database Information Disclosure Vulnerability
BID:11402
Info
IBM DB2 Universal Database Information Disclosure Vulnerability
| Bugtraq ID: | 11402 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 01 2004 12:00AM |
| Updated: | Sep 01 2004 12:00AM |
| Credit: | Discovery is credited to Chris Anley of NGSSoftware. |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 7.2 IBM DB2 Universal Database for Windows 7.1 |
| Not Vulnerable: | |
Discussion
IBM DB2 Universal Database Information Disclosure Vulnerability
An information disclosure vulnerability has been reported in IBM DB2. This vulnerability only exists when DB2 is installed on Microsoft Windows operating systems. This is due to a Windows permissions issue related to shared memory sections, culminating in authorized access to sensitive information.
This vulnerability allows local users to inappropriately connect to DB2 IPC resources, and to also read files that may contain potentially sensitive information. This may aid them in further attacks.
This issue was announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
An information disclosure vulnerability has been reported in IBM DB2. This vulnerability only exists when DB2 is installed on Microsoft Windows operating systems. This is due to a Windows permissions issue related to shared memory sections, culminating in authorized access to sensitive information.
This vulnerability allows local users to inappropriately connect to DB2 IPC resources, and to also read files that may contain potentially sensitive information. This may aid them in further attacks.
This issue was announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
Exploit / POC
IBM DB2 Universal Database Information Disclosure Vulnerability
The following attacks were published:
- Database usernames and passwords may be read from the 'DB2SHMSECURITYSERVICE' memory section.
- Various shared memory sections may be read allowing unauthorized access to query or query result data. The following examples were provided:
section read DB20QM
section read DB2GLBQ0QM
section read DB2SHMDB2_0APP
section read DB2SHMDB2_0APL00000003
section read DB2SHMDB2_0APL00000004
section read DB2SHMDB2_0APL00000005
The following attacks were published:
- Database usernames and passwords may be read from the 'DB2SHMSECURITYSERVICE' memory section.
- Various shared memory sections may be read allowing unauthorized access to query or query result data. The following examples were provided:
section read DB20QM
section read DB2GLBQ0QM
section read DB2SHMDB2_0APP
section read DB2SHMDB2_0APL00000003
section read DB2SHMDB2_0APL00000004
section read DB2SHMDB2_0APL00000005
Solution / Fix
IBM DB2 Universal Database Information Disclosure Vulnerability
Solution:
The vendor has released FixPak 7a to address this issue.
IBM DB2 Universal Database for Windows 8.0
IBM DB2 Universal Database for Windows 8.1
Solution:
The vendor has released FixPak 7a to address this issue.
IBM DB2 Universal Database for Windows 8.0
IBM DB2 Universal Database for Windows 8.1
References
IBM DB2 Universal Database Information Disclosure Vulnerability
References:
References:
- APARs included in DB2 UDB Version 8 FixPak 6a and FixPak 7a (IBM)
- DB2 APAR IY62300 (IBM)
- DB2 V8 FixPaks 6 and 7 replaced with FixPaks 6a and 7a (IBM)
- IBM responds to DB2 UDB security vulnerability reports (IBM)
- IBM DB2 Windows Permission Problems (#NISR05012005F) ("NGSSoftware Insight Security Research"
) - Patch available for critical IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
) - Patch available for IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
)