Vulnerability Description
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 Universal Database | <= 8.0 |
References
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U4951
- http://marc.info/?l=bugtraq&m=106010332721672&w=2
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U4951
- http://marc.info/?l=bugtraq&m=106010332721672&w=2
FAQ
What is CVE-2003-0898?
CVE-2003-0898 is a vulnerability with a CVSS score of 4.6 (MEDIUM). IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
How severe is CVE-2003-0898?
CVE-2003-0898 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0898?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2 Universal Database.