2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2011-1846" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2011-05-03T20:55:12.463" ,
2024-11-22 11:14:00 +00:00
"lastModified" : "2024-11-21T01:27:10.253" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information."
} ,
{
"lang" : "es" ,
"value" : "IBM DB2 v9.5 anterior a FP7 y v9.7 anterior a FP4 en Linux, UNIX y Windows no revoca correctamente la pertenencia a grupos, lo que permite a usuarios remotos autenticados ejecutar instrucciones non-DDL aprovech\u00e1ndose de la posesi\u00f3n heredada del rol anterior, una vulnerabilidad diferente de CVE-2011-0757. NOTA: algunos de estos detalles han sido obtenidos de informaci\u00f3n de terceros."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P" ,
2024-11-22 11:14:00 +00:00
"baseScore" : 6.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-11-22 11:14:00 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-264"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:*:fp6a:*:*:*:*:*:*" ,
"versionEndIncluding" : "9.5" ,
"matchCriteriaId" : "C8517013-E26A-43D1-B3E7-3A9905B5BD98"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "11ABF7CC-2FA5-4F2D-901A-2D0EF5B8E717"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "58147402-53D5-4F15-862B-EE3DCCD75E2C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "D3F3CB5E-D4FB-4C03-B108-06CC358B1F45"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp2a:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB2EA14A-878A-4D8D-B17A-568712D21C48"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "84C925CD-E753-401F-9EC0-6E3D9861C818"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp3a:*:*:*:*:*:*" ,
"matchCriteriaId" : "651D042C-A9F1-42D1-A6DD-95ADBCD08448"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp3b:*:*:*:*:*:*" ,
"matchCriteriaId" : "0A589323-B8B8-4CB4-B1A9-B9E771C99123"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp4:*:*:*:*:*:*" ,
"matchCriteriaId" : "61252AF9-A231-442A-A473-BA0608323BF2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp4a:*:*:*:*:*:*" ,
"matchCriteriaId" : "EB37A1AA-58F0-4A39-8E38-C70692CE67BF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp5:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D9D5B5B-8E23-4987-9BBE-8FE1F27CB1B5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.5:fp6:*:*:*:*:*:*" ,
"matchCriteriaId" : "E3E12C63-19FF-4BB9-9389-BF5E6B493F42"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:*:fp3:*:*:*:*:*:*" ,
"versionEndIncluding" : "9.7" ,
"matchCriteriaId" : "E4312D00-16F8-42CA-AB58-82F66781910F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE1C4DE6-EB32-4A31-9FAA-D8DA31D8CF05"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.7:fp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "00A16349-5CF1-4E75-A6EE-218E85049F62"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:db2:9.7:fp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "5335C017-52D9-45D4-BCEB-CBB51B7C88AE"
}
]
}
]
}
] ,
"references" : [
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/44229" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/bid/47525" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2011/1083" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/66980" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14688" ,
"source" : "cve@mitre.org"
2024-11-22 11:14:00 +00:00
} ,
{
"url" : "http://secunia.com/advisories/44229" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/47525" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2011/1083" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/66980" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14688" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}