VulnerabilityModified
CVE-2017-1520
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT.
LOW 3.7EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ibm/db2 · ibm/db2 connect
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22007186Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100684Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039308Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/129830Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22007186Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100684Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039308Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/129830Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.