7.2
CVSSv2

CVE-2017-1438

Published: 12/09/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm db2_connect 11.1.0.0

ibm db2 10.1

ibm db2 10.1.0.1

ibm db2 10.1.0.2

ibm db2_connect 10.5.0.4

ibm db2_connect 10.5.0.5

ibm db2_connect 10.5.0.6

ibm db2_connect 10.5.0.7

ibm db2_connect 9.7.0.4

ibm db2_connect 9.7.0.5

ibm db2_connect 9.7.0.6

ibm db2_connect 9.7.0.7

ibm db2 9.7.0.8

ibm db2 9.7.0.9

ibm db2 9.7.0.10

ibm db2_connect 10.1.0.1

ibm db2_connect 10.1.0.2

ibm db2_connect 10.1.0.3

ibm db2_connect 10.1.0.4

ibm db2_connect 10.1.0.5

ibm db2 10.5.0.3

ibm db2 10.5.0.4

ibm db2 10.5.0.5

ibm db2 10.5.0.6

ibm db2 9.7

ibm db2 9.7.0.1

ibm db2 9.7.0.2

ibm db2 9.7.0.3

ibm db2 11.1.0.0

ibm db2 10.1.0.3

ibm db2 10.1.0.5

ibm db2_connect 10.5

ibm db2_connect 10.5.0.2

ibm db2 10.5.0.1

ibm db2 10.5.0.7

ibm db2_connect 9.7.0.1

ibm db2_connect 9.7.0.3

ibm db2_connect 9.7.0.8

ibm db2_connect 9.7.0.10

ibm db2 9.7.0.5

ibm db2 9.7.0.7

ibm db2 9.7.0.11

ibm db2 10.1.0.4

ibm db2_connect 10.1

ibm db2_connect 10.5.0.1

ibm db2_connect 10.5.0.3

ibm db2 10.5

ibm db2 10.5.0.2

ibm db2_connect 9.7

ibm db2_connect 9.7.0.2

ibm db2_connect 9.7.0.9

ibm db2_connect 9.7.0.11

ibm db2 9.7.0.4

ibm db2 9.7.0.6