CVE-2005-4871
IBM DB2 8.1 - Privilege Escalation and Arbitrary File Read/Write via XML Functions
Title source: llmDescription
Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.
References (5)
Core 5
Core References
Patch x_refsource_misc
http://www.ngssoftware.com/advisories/db205012005I.txt
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110495620513954&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18761
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/12733/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/12170
Scores
EPSS
0.0108
EPSS Percentile
61.8%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/db2
8.1
Published
Dec 31, 2005
Tracked Since
Feb 18, 2026