IBM DB2 Universal Database Multiple Local Privilege Escalation Vulnerabilities
BID:22677
Info
IBM DB2 Universal Database Multiple Local Privilege Escalation Vulnerabilities
| Bugtraq ID: | 22677 |
| Class: | Unknown |
| CVE: |
CVE-2007-1087 CVE-2007-1088 CVE-2007-1086 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 22 2007 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Discovered by Joshua J. Drake (iDefense Labs). |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.12 IBM DB2 Universal Database for Windows 8.10 IBM DB2 Universal Database for Windows 8.2 IBM DB2 Universal Database for Windows 8.1.9 a IBM DB2 Universal Database for Windows 8.1.9 IBM DB2 Universal Database for Windows 8.1.8 a IBM DB2 Universal Database for Windows 8.1.8 IBM DB2 Universal Database for Windows 8.1.7 b IBM DB2 Universal Database for Windows 8.1.7 IBM DB2 Universal Database for Windows 8.1.6 c IBM DB2 Universal Database for Windows 8.1.6 IBM DB2 Universal Database for Windows 8.1.5 IBM DB2 Universal Database for Windows 8.1.4 IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 9.1 IBM DB2 Universal Database for Windows 8.1 FixPak 14 IBM DB2 Universal Database for Windows 8.0 FixPak 13 IBM DB2 Universal Database for Solaris 8.12 IBM DB2 Universal Database for Solaris 8.10 IBM DB2 Universal Database for Solaris 8.2 IBM DB2 Universal Database for Solaris 8.1.9 a IBM DB2 Universal Database for Solaris 8.1.9 IBM DB2 Universal Database for Solaris 8.1.8 a IBM DB2 Universal Database for Solaris 8.1.8 IBM DB2 Universal Database for Solaris 8.1.7 b IBM DB2 Universal Database for Solaris 8.1.7 IBM DB2 Universal Database for Solaris 8.1.6 c IBM DB2 Universal Database for Solaris 8.1.6 IBM DB2 Universal Database for Solaris 8.1.5 IBM DB2 Universal Database for Solaris 8.1.4 IBM DB2 Universal Database for Solaris 8.1 IBM DB2 Universal Database for Solaris 8.0 IBM DB2 Universal Database for Solaris 9.1 IBM DB2 Universal Database for Solaris 8.1 FixPak 14 IBM DB2 Universal Database for Solaris 8.0 FixPak 13 IBM DB2 Universal Database for Linux 8.12 IBM DB2 Universal Database for Linux 8.10 IBM DB2 Universal Database for Linux 8.2 IBM DB2 Universal Database for Linux 8.1.9 a IBM DB2 Universal Database for Linux 8.1.9 IBM DB2 Universal Database for Linux 8.1.8 a IBM DB2 Universal Database for Linux 8.1.8 IBM DB2 Universal Database for Linux 8.1.7 b IBM DB2 Universal Database for Linux 8.1.7 IBM DB2 Universal Database for Linux 8.1.6 c IBM DB2 Universal Database for Linux 8.1.6 IBM DB2 Universal Database for Linux 8.1.5 IBM DB2 Universal Database for Linux 8.1.4 IBM DB2 Universal Database for Linux 8.1 IBM DB2 Universal Database for Linux 8.0 IBM DB2 Universal Database for Linux 9.1 IBM DB2 Universal Database for Linux 8.1 FixPak 14 IBM DB2 Universal Database for Linux 8.0 FixPak 13 IBM DB2 Universal Database for HP-UX 8.12 IBM DB2 Universal Database for HP-UX 8.10 IBM DB2 Universal Database for HP-UX 8.2 IBM DB2 Universal Database for HP-UX 8.1.9 a IBM DB2 Universal Database for HP-UX 8.1.9 IBM DB2 Universal Database for HP-UX 8.1.8 a IBM DB2 Universal Database for HP-UX 8.1.8 IBM DB2 Universal Database for HP-UX 8.1.7 b IBM DB2 Universal Database for HP-UX 8.1.7 IBM DB2 Universal Database for HP-UX 8.1.6 c IBM DB2 Universal Database for HP-UX 8.1.6 IBM DB2 Universal Database for HP-UX 8.1.5 IBM DB2 Universal Database for HP-UX 8.1.4 IBM DB2 Universal Database for HP-UX 8.1 IBM DB2 Universal Database for HP-UX 8.0 IBM DB2 Universal Database for HP-UX 9.1 IBM DB2 Universal Database for HP-UX 8.1 FixPak 14 IBM DB2 Universal Database for HP-UX 8.0 FixPak 13 IBM DB2 Universal Database for AIX 8.12 IBM DB2 Universal Database for AIX 8.10 IBM DB2 Universal Database for AIX 8.2 IBM DB2 Universal Database for AIX 8.1.9 a IBM DB2 Universal Database for AIX 8.1.9 IBM DB2 Universal Database for AIX 8.1.8 a IBM DB2 Universal Database for AIX 8.1.8 IBM DB2 Universal Database for AIX 8.1.7 b IBM DB2 Universal Database for AIX 8.1.7 IBM DB2 Universal Database for AIX 8.1.6 c IBM DB2 Universal Database for AIX 8.1.6 IBM DB2 Universal Database for AIX 8.1.5 IBM DB2 Universal Database for AIX 8.1.4 IBM DB2 Universal Database for AIX 8.1 IBM DB2 Universal Database for AIX 8.0 IBM DB2 Universal Database for AIX 9.1 FixPack 2 IBM DB2 Universal Database for AIX 8.1 FixPak 14 IBM DB2 Universal Database for AIX 8.0 FixPak 13 |
| Not Vulnerable: |
IBM DB2 Universal Database for Windows 9.0 Fix Pack 2 IBM DB2 Universal Database for Solaris 9.0 Fix Pack 2 IBM DB2 Universal Database for Linux 9.0 Fix Pack 2 IBM DB2 Universal Database for HP-UX 9.0 Fix Pack 2 IBM DB2 Universal Database for AIX 9.0 Fix Pack 2 |
Discussion
IBM DB2 Universal Database Multiple Local Privilege Escalation Vulnerabilities
IBM DB2 is prone to multiple local privilege-escalation vulnerabilities that allow an attacker to completely compromise a vulnerable computer.
These issues affect DB2 9.1 and 8x running on all supported platforms.
IBM DB2 is prone to multiple local privilege-escalation vulnerabilities that allow an attacker to completely compromise a vulnerable computer.
These issues affect DB2 9.1 and 8x running on all supported platforms.
Exploit / POC
IBM DB2 Universal Database Multiple Local Privilege Escalation Vulnerabilities
Some of these issues may not require exploit code and may be triggered using existing operating system utilities.
Currently we are not aware of any exploits for the memory-corruption issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require exploit code and may be triggered using existing operating system utilities.
Currently we are not aware of any exploits for the memory-corruption issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM DB2 Universal Database Multiple Local Privilege Escalation Vulnerabilities
Solution:
IBM has released version 9.0 Fixpak 2 to address these issues in version 9.2. A fix for version 8 will be released in April.
Solution:
IBM has released version 9.0 Fixpak 2 to address these issues in version 9.2. A fix for version 8 will be released in April.
References
IBM DB2 Universal Database Multiple Local Privilege Escalation Vulnerabilities
References:
References:
- DB2 Technical Support (IBM)
- SECURITY APAR IY94833 (IBM)
- IBM DB2 Universal Database DB2INSTANCE File Creation Vulnerability (iDefense Labs
) - iDefense Security Advisory 02.22.07: IBM DB2 Universal Database Multiple Privile (iDefense Labs
)