VulnerabilityModified
CVE-2010-3194
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
HIGH 7.5EPSS 1.84%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/db2
- Source
- cve@mitre.org
References
- ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
- http://secunia.com/advisories/41218Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65749
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65756Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65762Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21426108Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21432298Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2225Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61445
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13841
- ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
- http://secunia.com/advisories/41218Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65749
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65756Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65762Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21426108Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21432298Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2225Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61445
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13841
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.