CVE-2008-3857

The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2_universal_database:9.1:*:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:hp_ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:windows:*:*:*:*:*

History

No history.

Information

Published : 2008-08-28 17:41

Updated : 2024-02-04 17:33


NVD link : CVE-2008-3857

Mitre link : CVE-2008-3857

CVE.ORG link : CVE-2008-3857


JSON object : View

Products Affected

ibm

  • db2_universal_database
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor