Vulnerability Name: | CVE-2013-6744 (CCN-89860) | ||||||||
Assigned: | 2013-11-08 | ||||||||
Published: | 2014-05-26 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority. | ||||||||
CVSS v3 Severity: | 8.0 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 8.5 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C) 6.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-6744 Source: AIXAPAR Type: UNKNOWN IC98849 Source: AIXAPAR Type: UNKNOWN IC99478 Source: AIXAPAR Type: UNKNOWN IC99480 Source: AIXAPAR Type: UNKNOWN IC99481 Source: CCN Type: IBM Security Bulletin 1673947 Escalation of Privilege Vulnerability in IBM DB2 Stored Procedure Infrastructure on Windows (CVE-2013-6744) Source: CONFIRM Type: Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg1IC99480 Source: CONFIRM Type: UNKNOWN http://www.ibm.com/support/docview.wss?uid=swg21610582#4 Source: CONFIRM Type: UNKNOWN http://www.ibm.com/support/docview.wss?uid=swg21673947 Source: CCN Type: BID-67616 IBM DB2 and DB2 Connect CVE-2013-6744 Privilege Escalation Vulnerability Source: XF Type: UNKNOWN ibm-db2-cve20136744-priv-escalation(89860) Source: XF Type: UNKNOWN ibm-db2-cve20136744-priv-escalation(89860) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |