IBM DB2 Windows XP Simple File Sharing Authentication Bypass Vulnerability
BID:15452
Info
IBM DB2 Windows XP Simple File Sharing Authentication Bypass Vulnerability
| Bugtraq ID: | 15452 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2005 12:00AM |
| Updated: | Nov 16 2005 12:00AM |
| Credit: | Discovery is credited to David Litchfield of NGSSoftware. |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.10 IBM DB2 Universal Database for Windows 8.2 IBM DB2 Universal Database for Windows 8.1.9 a IBM DB2 Universal Database for Windows 8.1.9 IBM DB2 Universal Database for Windows 8.1.8 a IBM DB2 Universal Database for Windows 8.1.8 IBM DB2 Universal Database for Windows 8.1.7 b IBM DB2 Universal Database for Windows 8.1.7 IBM DB2 Universal Database for Windows 8.1.6 c IBM DB2 Universal Database for Windows 8.1.6 IBM DB2 Universal Database for Windows 8.1.5 IBM DB2 Universal Database for Windows 8.1.4 IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 7.2 IBM DB2 Universal Database for Windows 7.1 |
| Not Vulnerable: | |
Discussion
IBM DB2 Windows XP Simple File Sharing Authentication Bypass Vulnerability
IBM DB2 is affected by an authentication bypass vulnerability when run on Microsoft Windows XP computers that have Simple File Sharing enabled.
This vulnerability may let attackers gain unauthorized access to the database using the Windows XP Guest account. This could be exploited with a custom client that will authenticate the attacker as the Guest account.
The researcher who discovered this issue has not provided a conclusive list of affected IBM DB2 products. For the time being, all versions that run on Windows XP are assumed to be affected. If contrary information is made available, this BID will be updated accordingly.
IBM DB2 is affected by an authentication bypass vulnerability when run on Microsoft Windows XP computers that have Simple File Sharing enabled.
This vulnerability may let attackers gain unauthorized access to the database using the Windows XP Guest account. This could be exploited with a custom client that will authenticate the attacker as the Guest account.
The researcher who discovered this issue has not provided a conclusive list of affected IBM DB2 products. For the time being, all versions that run on Windows XP are assumed to be affected. If contrary information is made available, this BID will be updated accordingly.
Exploit / POC
IBM DB2 Windows XP Simple File Sharing Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM DB2 Windows XP Simple File Sharing Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM DB2 Windows XP Simple File Sharing Authentication Bypass Vulnerability
References:
References: