CVE-2004-0795: High severity IBM DB2 Universal Database vulnerability
Published Aug 20, 2004
·Updated
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.
Affected Software
1 affected component
IBM DB2 Universal Database=8.1
Remediation
Patch Available
Event History
Aug 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0795?
CVE-2004-0795 has a medium severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2004-0795?
To fix CVE-2004-0795, it is recommended to apply the latest security updates and patches provided by IBM for DB2 8.1.
3
What type of vulnerability is CVE-2004-0795?
CVE-2004-0795 is a privilege escalation vulnerability affecting the DB2 remote command server.
4
Who is affected by CVE-2004-0795?
CVE-2004-0795 specifically affects users of IBM DB2 Universal Database version 8.1 on AIX.
5
What can an attacker do with CVE-2004-0795?
An attacker can leverage CVE-2004-0795 to execute commands with elevated privileges through the DB2 remote command server.