CVE-2003-0898

IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2_universal_database:*:*:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:7.1:*:linux:*:*:*:*:*

History

20 Nov 2024, 23:45

Type Values Removed Values Added
References () ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt - () ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt -
References () http://marc.info/?l=bugtraq&m=106010332721672&w=2 - () http://marc.info/?l=bugtraq&m=106010332721672&w=2 -

Information

Published : 2003-11-17 05:00

Updated : 2024-11-20 23:45


NVD link : CVE-2003-0898

Mitre link : CVE-2003-0898

CVE.ORG link : CVE-2003-0898


JSON object : View

Products Affected

ibm

  • db2_universal_database