CVE-2008-1998
IBM DB2 <8.FP16, <9.1.FP4a, <9.5.FP1 - Privilege Escalation
Title source: llmDescription
The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
References (10)
Core 10
Core References
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06976
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10776
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06977
Third Party Advisory x_refsource_misc
http://www.appsecinc.com/resources/alerts/db2/2008-03.shtml
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/3840
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/491073/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/29784
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/28836
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/29022
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41960
Scores
EPSS
0.0250
EPSS Percentile
83.0%
Details
CWE
CWE-264
Status
published
Products (3)
ibm/db2
8.0 fp1 (22 CPE variants)
ibm/db2
9.1 fp1 (5 CPE variants)
ibm/db2
9.5
Published
Apr 28, 2008
Tracked Since
Feb 18, 2026