{ "id": "CVE-2014-0919", "sourceIdentifier": "psirt@us.ibm.com", "published": "2015-05-08T01:59:00.080", "lastModified": "2016-11-28T19:10:42.190", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities." }, { "lang": "es", "value": "IBM DB2 9.5 hasta 10.5 en Linux, UNIX, y Windows almacena contrase\u00f1as durante el procesamiento de ciertas declaraciones SQL mediante las instalaciones de monitorizaci\u00f3n y auditoria, lo que permite a usuarios remotos autenticados obtener informaci\u00f3n sensible a trav\u00e9s de comandos asociados con estas instalaciones." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-200" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:advanced_enterprise:*:*:*", "matchCriteriaId": "7D6DD3FF-5AD3-4D39-9CEE-838630A45C61" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:advanced_workgroup:*:*:*", "matchCriteriaId": "AD3706B1-232E-411A-9F42-452CEF827341" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:enterprise:*:*:*", "matchCriteriaId": "0AEA6FC2-8A75-4C22-92B8-8F7243B20886" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:express:*:*:*", "matchCriteriaId": "70DD1608-0865-451C-989C-67D7E7FDADBB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:workgroup:*:*:*", "matchCriteriaId": "55AB0632-CDAF-43CB-A614-33E5687D6A45" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise:*:*:*", "matchCriteriaId": "3D9E7D2A-42B9-4D07-A107-BBD839E59858" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup:*:*:*", "matchCriteriaId": "FD27164C-7554-46E1-B755-27C74D2EC3B7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise:*:*:*", "matchCriteriaId": "F199F7B4-F273-4D45-AE08-7B5DAE6E0794" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*", "matchCriteriaId": "ACEB3F4A-6411-4456-9B89-A43562189BD3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup:*:*:*", "matchCriteriaId": "1749B7DC-08BB-474B-BA5A-52602459C8EC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_enterprise:*:*:*", "matchCriteriaId": "025FA405-0FD2-4B19-8FA4-15581085BD15" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_workgroup:*:*:*", "matchCriteriaId": "F425C545-39CD-483C-97A3-BE0DC3EE63DB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:enterprise:*:*:*", "matchCriteriaId": "6A6A7680-D883-414F-965B-1D6136760CA5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:express:*:*:*", "matchCriteriaId": "76107CFE-EB32-4AF6-9AF9-F16238F9C671" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:workgroup:*:*:*", "matchCriteriaId": "7D1225B0-DBFF-4A13-93CB-1B64AF9ACE47" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_enterprise:*:*:*", "matchCriteriaId": "2ECC11D3-7D77-4823-8B34-DD76E131D74C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_workgroup:*:*:*", "matchCriteriaId": "E1D36687-32AF-43E2-97D9-FDF602F89318" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:enterprise:*:*:*", "matchCriteriaId": "DD80ADF4-35D3-4534-AACD-C00D80870723" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:express:*:*:*", "matchCriteriaId": "8D274B00-C986-4A5D-94B2-79F4A613D951" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:workgroup:*:*:*", "matchCriteriaId": "67A935CA-7AF6-4DA9-958E-DF4BC8E2B3BF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_enterprise:*:*:*", "matchCriteriaId": "A6B1A4DC-7062-4349-8D1A-3DE4B0E68FC8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_workgroup:*:*:*", "matchCriteriaId": "B3681F43-F23B-413D-B871-A40821F4988B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:enterprise:*:*:*", "matchCriteriaId": "AE645126-ECD0-40FB-B2BA-5C9EF33EBE69" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:express:*:*:*", "matchCriteriaId": "9AFEA656-426C-4F18-9737-8985531C7A93" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:workgroup:*:*:*", "matchCriteriaId": "09B0333F-0E27-40B3-A0DC-618BEA97CBC2" } ] } ] } ], "references": [ { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07397", "source": "psirt@us.ibm.com" }, { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07547", "source": "psirt@us.ibm.com" }, { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07552", "source": "psirt@us.ibm.com" }, { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07553", "source": "psirt@us.ibm.com" }, { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07554", "source": "psirt@us.ibm.com" }, { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21698021", "source": "psirt@us.ibm.com", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/74217", "source": "psirt@us.ibm.com" }, { "url": "http://www.securitytracker.com/id/1032247", "source": "psirt@us.ibm.com" } ] }