CVE-2005-4871

IBM DB2 8.1 - Privilege Escalation and Arbitrary File Read/Write via XML Functions

Title source: llm
STIX 2.1

Description

Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110495620513954&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18761
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12733/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12170

Scores

EPSS 0.0108
EPSS Percentile 61.8%

Details

CWE
CWE-264
Status published
Products (1)
ibm/db2 8.1
Published Dec 31, 2005
Tracked Since Feb 18, 2026