6.9
CVSSv2

CVE-2016-5995

Published: 01/10/2016 Updated: 30/07/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.3 | Impact Score: 5.9 | Exploitability Score: 1.3
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm db2 11.1.0.0

ibm db2_connect 11.1.0.0

ibm db2_connect 10.1.0.5

ibm db2_connect 10.1.0.4

ibm db2_connect 10.1.0.2

ibm db2_connect 10.1.0.1

ibm db2 10.1.0.2

ibm db2 10.1.0.1

ibm db2 10.1.0.5

ibm db2 10.1.0.3

ibm db2 10.1.0.4

ibm db2 10.1

ibm db2_connect 10.5.0.4

ibm db2_connect 10.5.0.3

ibm db2_connect 10.5.0.2

ibm db2_connect 10.5.0.1

ibm db2_connect 10.5

ibm db2 10.5.0.3

ibm db2 10.5.0.2

ibm db2 10.5.0.1

ibm db2 10.5.0.7

ibm db2 10.5.0.6

ibm db2 10.5.0.5

ibm db2 10.5

ibm db2_connect 9.7.0.5

ibm db2_connect 9.7.0.4

ibm db2_connect 9.7.0.8

ibm db2_connect 9.7.0.7

ibm db2_connect 9.7.0.6

ibm db2_connect 9.7.0.10

ibm db2_connect 9.7.0.9

ibm db2_connect 9.7.0.2

ibm db2_connect 9.7.0.1

ibm db2_connect 10.1.0.3

ibm db2_connect 10.5.0.5

ibm db2 10.5.0.4

ibm db2_connect 9.7.0.11

ibm db2_connect 9.7.0.3

ibm db2 9.7.0.10

ibm db2 9.7.0.9

ibm db2 9.7.0.8

ibm db2 9.7.0.1

ibm db2 9.7.0.11

ibm db2 9.7.0.4

ibm db2 9.7.0.3

ibm db2 9.7.0.7

ibm db2 9.7.0.6

ibm db2 9.7.0.5

ibm db2 9.7.0.2

ibm db2_connect 10.5.0.7

ibm db2_connect 10.5.0.6

ibm db2_connect 10.1

ibm db2 9.7

ibm db2_connect 9.7