2009-4327 | IBM DB2 input validation (BID-37332 / XFDB-55023)
CVSS Meta Temp Score | Current Exploit Price (≈) | CTI Interest Score |
---|---|---|
5.1 | $0-$5k | 0.88 |
A vulnerability classified as problematic was found in IBM DB2 9.5/9.7 (Database Software). This vulnerability affects an unknown part. The manipulation with an unknown input leads to a privilege escalation vulnerability. The CWE definition for the vulnerability is CWE-20. As an impact it is known to affect availability.
The weakness was released 12/16/2009 (Website). The advisory is available at www-01.ibm.com. This vulnerability was named CVE-2009-4327 since 12/16/2009. The exploitation appears to be easy. The attack can be initiated remotely. No form of authentication is required for a successful exploitation. The technical details are unknown and an exploit is not available.
The vulnerability scanner Nessus provides a plugin with the ID 43172 (IBM DB2 9.5 Databases.
Upgrading to version 9.5 eliminates this vulnerability.
The vulnerability is also documented in the databases at X-Force (55023), Vulnerability Center (SBV-26218) and Tenable (43172). Entries connected to this vulnerability are available at 48412, 51324, 51323 and 51174.
Type
Vendor
Name
VulDB Meta Base Score: 5.3
VulDB Meta Temp Score: 5.1
VulDB Base Score: 5.3
VulDB Temp Score: 5.1
VulDB Vector: 🔍
VulDB Reliability: 🔍
AV | AC | Au | C | I | A |
---|---|---|---|---|---|
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
Vector | Complexity | Authentication | Confidentiality | Integrity | Availability |
---|---|---|---|---|---|
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
VulDB Base Score: 🔍
VulDB Temp Score: 🔍
VulDB Reliability: 🔍
NVD Base Score: 🔍
Class: Privilege escalation
CWE: CWE-20
ATT&CK: Unknown
Local: No
Remote: Yes
Availability: 🔍
Status: Not defined
Price Prediction: 🔍
Current Price Estimation: 🔍
0-Day | unlock | unlock | unlock | unlock |
---|---|---|---|---|
Today | unlock | unlock | unlock | unlock |
Nessus ID: 43172
Nessus Name: IBM DB2 9.5 Nessus File: 🔍
Nessus Risk: 🔍
Nessus Family: 🔍
OpenVAS ID: 901075
OpenVAS Name: IBM DB2 Multiple Unspecified Vulnerabilities (Linux)
OpenVAS File: 🔍
OpenVAS Family: 🔍
Threat Intelligence
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍Recommended: Upgrade
Status: 🔍
0-Day Time: 🔍
Upgrade: DB2 9.5
12/14/2009 🔍
12/14/2009 🔍
12/16/2009 🔍
12/16/2009 🔍
12/16/2009 🔍
06/30/2010 🔍
03/18/2015 🔍
08/28/2021 🔍Vendor: https://www.ibm.com/
Advisory: www-01.ibm.com
Status: Not defined
Confirmation: 🔍
CVE: CVE-2009-4327 (🔍)
X-Force: 55023
Vulnerability Center: 26218 – IBM DB2 9.5-9.5 FP4 and 9.7 Remote Denial of Service (DoS) Vulnerability via Unspecified Vectors, Medium
SecurityFocus: 37332 – IBM DB2 prior to 9.5 Fix Pack 5 Multiple Unspecified Security Vulnerabilities
See also: 🔍
Created: 03/18/2015 15:15
Updated: 08/28/2021 19:45
Changes: (1) source_nessus_risk
Complete: 🔍
Comments
Download it now for free!
No comments yet. Languages: . Please log in to comment.