Vulnerability Name: | CVE-2018-1685 (CCN-145502) | ||||||||||||
Assigned: | 2017-12-13 | ||||||||||||
Published: | 2018-09-19 | ||||||||||||
Updated: | 2018-11-19 | ||||||||||||
Summary: | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-1685 Source: BID Type: Third Party Advisory, VDB Entry 105395 Source: CCN Type: BID-105395 IBM DB2 'db2cacpy' CVE-2018-1685 Local Information Disclosure Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041671 Source: XF Type: UNKNOWN ibm-db2-cve20181685-info-disc(145502) Source: XF Type: VDB Entry, Vendor Advisory ibm-db2-cve20181685-info-disc(145502) Source: CCN Type: IBM Security Bulletin 729979 (DB2 for Linux, UNIX and Windows) Privilege escalation in IBM Db2 tool db2cacpy (CVE-2018-1685). Source: CONFIRM Type: Vendor Advisory https://www.ibm.com/support/docview.wss?uid=ibm10729979 Source: CCN Type: IBM Security Bulletin 793907 (Spectrum Protect) Multiple Db2 vulnerabilities affect the IBM Spectrum Protect Server (CVE-2018-1685, CVE-2018-1710, CVE-2018-1711, CVE-2018-1780, CVE-2018-1781, CVE-2018-1799, CVE-2018-1802, CVE-2018-1834, CVE-2018-1857, CVE-2018-1897) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |