The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 01:19
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT - | |
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68463 - | |
| References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14707 - | 
Information
                Published : 2010-10-05 18:00
Updated : 2025-04-11 00:51
NVD link : CVE-2010-3733
Mitre link : CVE-2010-3733
CVE.ORG link : CVE-2010-3733
JSON object : View
Products Affected
                ibm
- db2
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
