Vulnerability Name:
CVE-2017-1452 (CCN-128180)
Assigned:
2016-11-30
Published:
2017-09-07
Updated:
2019-10-03
Summary:
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.
CVSS v3 Severity:
7.8 High
(CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
)
6.8 Medium
(Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
6.7 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
)
5.8 Medium
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
7.2 High
(CVSS v2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
6.8 Medium
(CCN CVSS v2 Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:C
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Type:
CWE-noinfo
Vulnerability Consequences:
Gain Privileges
References:
Source: MITRE
Type: CNA
CVE-2017-1452
Source: CCN
Type: IBM Security Bulletin 2006109 (DB2 for Linux, UNIX and Windows)
IBM Db2 vulnerability allows local user to overwrite Db2 files. (CVE-2017-1452)
Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=swg22006109
Source: CCN
Type: IBM Security Bulletin 2008363 (BigInsights)
BigInsights is affected by multiple vulnerabilities in Db2
Source: CCN
Type: IBM Security Bulletin 2008900 (Monitoring)
Security vulnerabilities have been identified in DB2 which is shipped with IBM Performance Management products
Source: CCN
Type: IBM Security Bulletin 2013377 (Spectrum Protect)
Multiple DB2 vulnerabilities affect IBM Spectrum Protect (formerly Tivoli Storage Manger) Server (CVE-2017-1434, CVE-2017-1438, CVE-2017-1439, CVE-2017-1451, CVE-2017-1452)
Source: BID
Type: Third Party Advisory, VDB Entry
100698
Source: CCN
Type: BID-100698
IBM DB2 CVE-2017-1452 Local Privilege Escalation Vulnerability
Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1039299
Source: MISC
Type: Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/128180
Source: XF
Type: UNKNOWN
ibm-db2-cve20171452-priv-escalation(128180)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:ibm:db2:9.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.8:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.9:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.9:a:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.10:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:9.7.0.11:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.1:*:*:*:*:-:*:*
OR
cpe:/a:ibm:db2:10.1.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.1.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.1.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.1.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.1.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.3:a:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:10.5.0.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2:11.1.0.0:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.8:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.9:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.10:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:9.7.0.11:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.1.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.1.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.1.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.1.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.1.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5.0.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:10.5.0.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_connect:11.1.0.0:*:*:*:*:*:*:*
AND
cpe:/o:linux:linux_kernel:-:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows:-:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
ibm
db2 9.7
ibm
db2 9.7.0.1
ibm
db2 9.7.0.2
ibm
db2 9.7.0.3
ibm
db2 9.7.0.4
ibm
db2 9.7.0.5
ibm
db2 9.7.0.6
ibm
db2 9.7.0.7
ibm
db2 9.7.0.8
ibm
db2 9.7.0.9
ibm
db2 9.7.0.9 a
ibm
db2 9.7.0.10
ibm
db2 9.7.0.11
ibm
db2 10.1
ibm
db2 10.1.0.1
ibm
db2 10.1.0.2
ibm
db2 10.1.0.3
ibm
db2 10.1.0.4
ibm
db2 10.1.0.5
ibm
db2 10.5
ibm
db2 10.5.0.1
ibm
db2 10.5.0.2
ibm
db2 10.5.0.3
ibm
db2 10.5.0.3 a
ibm
db2 10.5.0.4
ibm
db2 10.5.0.5
ibm
db2 10.5.0.6
ibm
db2 10.5.0.7
ibm
db2 11.1.0.0
ibm
db2 connect 9.7
ibm
db2 connect 9.7.0.1
ibm
db2 connect 9.7.0.2
ibm
db2 connect 9.7.0.3
ibm
db2 connect 9.7.0.4
ibm
db2 connect 9.7.0.5
ibm
db2 connect 9.7.0.6
ibm
db2 connect 9.7.0.7
ibm
db2 connect 9.7.0.8
ibm
db2 connect 9.7.0.9
ibm
db2 connect 9.7.0.10
ibm
db2 connect 9.7.0.11
ibm
db2 connect 10.1
ibm
db2 connect 10.1.0.1
ibm
db2 connect 10.1.0.2
ibm
db2 connect 10.1.0.3
ibm
db2 connect 10.1.0.4
ibm
db2 connect 10.1.0.5
ibm
db2 connect 10.5
ibm
db2 connect 10.5.0.1
ibm
db2 connect 10.5.0.2
ibm
db2 connect 10.5.0.3
ibm
db2 connect 10.5.0.4
ibm
db2 connect 10.5.0.5
ibm
db2 connect 10.5.0.6
ibm
db2 connect 10.5.0.7
ibm
db2 connect 11.1.0.0
linux
linux kernel -
microsoft
windows -