First published: Fri Aug 20 2004(Updated: )
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0795 has a medium severity rating due to its potential for privilege escalation.
To fix CVE-2004-0795, it is recommended to apply the latest security updates and patches provided by IBM for DB2 8.1.
CVE-2004-0795 is a privilege escalation vulnerability affecting the DB2 remote command server.
CVE-2004-0795 specifically affects users of IBM DB2 Universal Database version 8.1 on AIX.
An attacker can leverage CVE-2004-0795 to execute commands with elevated privileges through the DB2 remote command server.