René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

210 lines
7.0 KiB
JSON

{
"id": "CVE-2009-4334",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-12-16T18:30:00.593",
"lastModified": "2010-06-29T04:00:00.000",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file."
},
{
"lang": "es",
"value": "El componente Self Tuning Memory Manager (STMM) en IBM DB2 v9.1 anterior a FP8, v9.5 anterior FP5 y v9.7 anterior a FP1, usa permisos 0666 para el archivos de log STMM, lo que permite a usuarios locales provocar una denegaci\u00f3n de servicio o tener un impacto desconocido relacionado con este archivo."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 4.6
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.9,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:*",
"matchCriteriaId": "7B28091A-8772-41DC-9D91-D5359CDDA7A9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:*",
"matchCriteriaId": "2AF419E7-F2B5-4E2A-B85D-C0EC6C1DEA4F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp2:*:*:*:*:*:*",
"matchCriteriaId": "95BBA3F1-C276-4C30-BFE5-9CE212BEBEFA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp3:*:*:*:*:*:*",
"matchCriteriaId": "4DF01163-F805-4FC8-9836-462034D1B5CF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp3a:*:*:*:*:*:*",
"matchCriteriaId": "E570E88C-35F8-4E12-8121-20536AC8A0AB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp4:*:*:*:*:*:*",
"matchCriteriaId": "757E30FB-2EFB-4B3D-9931-17D584D433A2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp4a:*:*:*:*:*:*",
"matchCriteriaId": "B31F9D02-25FD-4ED1-9D1C-B244BC9426B6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp5:*:*:*:*:*:*",
"matchCriteriaId": "47455B4A-6E10-417F-9974-B0AA7F3180FE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp6:*:*:*:*:*:*",
"matchCriteriaId": "84156C5B-EFC6-4733-A868-C3C51CFBA7CD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp6a:*:*:*:*:*:*",
"matchCriteriaId": "FA8ABABB-F84D-41F0-A894-56911AF6E7E7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.1:fp7:*:*:*:*:*:*",
"matchCriteriaId": "3D511307-1EBB-408B-BCDE-C6BEFCF154C5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:*",
"matchCriteriaId": "11ABF7CC-2FA5-4F2D-901A-2D0EF5B8E717"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.5:fp1:*:*:*:*:*:*",
"matchCriteriaId": "58147402-53D5-4F15-862B-EE3DCCD75E2C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.5:fp2:*:*:*:*:*:*",
"matchCriteriaId": "D3F3CB5E-D4FB-4C03-B108-06CC358B1F45"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.5:fp2a:*:*:*:*:*:*",
"matchCriteriaId": "CB2EA14A-878A-4D8D-B17A-568712D21C48"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.5:fp3:*:*:*:*:*:*",
"matchCriteriaId": "84C925CD-E753-401F-9EC0-6E3D9861C818"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.5:fp3a:*:*:*:*:*:*",
"matchCriteriaId": "651D042C-A9F1-42D1-A6DD-95ADBCD08448"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.5:fp3b:*:*:*:*:*:*",
"matchCriteriaId": "0A589323-B8B8-4CB4-B1A9-B9E771C99123"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*",
"matchCriteriaId": "CE1C4DE6-EB32-4A31-9FAA-D8DA31D8CF05"
}
]
}
]
}
],
"references": [
{
"url": "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT",
"source": "cve@mitre.org"
},
{
"url": "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT",
"source": "cve@mitre.org"
},
{
"url": "ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT",
"source": "cve@mitre.org"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IC64019",
"source": "cve@mitre.org"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50355",
"source": "cve@mitre.org"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21293566",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21412902",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/37332",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/3520",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}