CVE-2005-4868
HIGHIBM DB2 Universal Database 8.1 - Unauthorized Access via Shared Memory Permissions
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4868. PoCs published by Chris Anley.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in IBM DB2 on Windows due to improper permissions on shared memory sections, allowing local users to read sensitive data such as credentials and query results.
Description
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
Exploits (1)
This is a writeup describing an information disclosure vulnerability in IBM DB2 on Windows due to improper permissions on shared memory sections, allowing local users to read sensitive data such as credentials and query results.
References (6)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H