CVE-2008-1998

IBM DB2 <8.FP16, <9.1.FP4a, <9.5.FP1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.

References (10)

Core 10
Core References
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06976
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10776
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06977
Third Party Advisory x_refsource_misc
http://www.appsecinc.com/resources/alerts/db2/2008-03.shtml
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3840
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/491073/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29784
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28836
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29022
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41960

Scores

EPSS 0.0250
EPSS Percentile 83.0%

Details

CWE
CWE-264
Status published
Products (3)
ibm/db2 8.0 fp1 (22 CPE variants)
ibm/db2 9.1 fp1 (5 CPE variants)
ibm/db2 9.5
Published Apr 28, 2008
Tracked Since Feb 18, 2026