Vulnerability Name:

CVE-2007-4418 (CCN-36109)

Assigned:2007-08-15
Published:2007-08-15
Updated:2017-07-29
Summary:IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors.
Note: this issue is probably related to CVE-2007-1089, but this is uncertain due to lack of details.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P)
4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Other
References:Source: MITRE
Type: CNA
CVE-2007-4418

Source: CCN
Type: SA26471
IBM DB2 Multiple Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
26471

Source: AIXAPAR
Type: UNKNOWN
JR25940

Source: CCN
Type: APAR JR25940
SECURITY VULNERABILITY RELATED TO INCORRECT AUTHORIZATION CHECKS

Source: CONFIRM
Type: UNKNOWN
http://www-1.ibm.com/support/docview.wss?uid=swg21255352

Source: CCN
Type: VIM Mailing list, Sat Aug 18 21:05:56 UTC 2007
Recent DB2 Vulnerabilities

Source: MLIST
Type: UNKNOWN
[VIM] 20070821 Recent DB2 Vulnerabilities

Source: BID
Type: UNKNOWN
25339

Source: CCN
Type: BID-25339
IBM DB2 Universal Database Multiple Unspecified Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2007-2912

Source: XF
Type: UNKNOWN
db2-select-unspecified(36109)

Source: XF
Type: UNKNOWN
db2-select-unspecified(36109)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:db2_universal_database:*:fp14:*:*:*:*:*:* (Version <= 8.0)

  • Configuration CCN 1:
  • cpe:/a:ibm:db2_universal_database:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:9.1:fp3:aix:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:9.1::fp2:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.0:fp14:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.0:fp13:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.0:fp9:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm db2 universal database * fp14
    ibm db2 universal database 8.0
    ibm db2 universal database 9.1
    ibm db2 universal database 9.1 fp3
    ibm db2 universal database 9.1
    ibm db2 universal database 8.0 fp14
    ibm db2 universal database 8.0 fp13
    ibm db2 universal database 8.0 fp9