Executive Summary

Informations
Name CVE-2007-4275 First vendor Publication 2007-08-18
Vendor Cve Last vendor Modification 2017-07-29

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 6.9 Attack Range Local
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4275

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 201

Open Source Vulnerability Database (OSVDB)

Id Description
40983 IBM DB2 Universal Database db2pd Search Path Subversion Local Privilege Escal...

40982 IBM DB2 Universal Database db2licm Search Path Subversion Local Privilege Esc...

40981 IBM DB2 Universal Database on AIX Unspecified Search Path Subversion Local Pr...

40980 IBM DB2 Universal Database on Unix FMP Startup Search Path Subversion Local P...

Nessus® Vulnerability Scanner

Date Description
2007-08-20 Name : The remote database server is affected by multiple vulnerabilities.
File : db2_9fp3.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
AIXAPAR http://www-1.ibm.com/support/docview.wss?uid=swg1IY97922
http://www-1.ibm.com/support/docview.wss?uid=swg1IY97936
http://www-1.ibm.com/support/docview.wss?uid=swg1IY98176
http://www-1.ibm.com/support/docview.wss?uid=swg1IY98206
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ01923
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ02067
BID http://www.securityfocus.com/bid/25339
CONFIRM http://www-1.ibm.com/support/docview.wss?uid=swg21255352
http://www-1.ibm.com/support/docview.wss?uid=swg21255607
IDEFENSE http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=582
MLIST http://www.attrition.org/pipermail/vim/2007-August/001765.html
SECTRACK http://securitytracker.com/id?1018581
SECUNIA http://secunia.com/advisories/26471
VUPEN http://www.vupen.com/english/advisories/2007/2912
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/36062
https://exchange.xforce.ibmcloud.com/vulnerabilities/36064

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2024-02-17 01:06:44
  • Multiple Updates
2021-05-04 12:06:14
  • Multiple Updates
2021-04-22 01:06:47
  • Multiple Updates
2020-05-23 01:38:36
  • Multiple Updates
2020-05-23 00:20:16
  • Multiple Updates
2017-07-29 12:02:27
  • Multiple Updates
2016-04-26 16:28:35
  • Multiple Updates
2014-02-17 10:41:17
  • Multiple Updates
2013-05-11 10:33:46
  • Multiple Updates