First published: Fri Feb 23 2007(Updated: )
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | ||
IBM AIX | ||
Linux Kernel | =2.6.18.0 | |
Linux Kernel | =2.6.18.1 | |
Linux Kernel | =2.6.18.2 | |
Linux Kernel | =2.6.18.3 | |
Linux Kernel | =2.6.18.4 | |
Linux Kernel | =2.6.18.5 | |
Linux Kernel | =2.6.18.6 | |
Linux Kernel | =2.6.18.7 | |
Linux Kernel | =2.6.19 | |
Linux Kernel | =2.6.19.1 | |
Linux Kernel | =2.6.19.2 | |
Linux Kernel | =2.6.19.3 | |
Linux Kernel | =2.6.19.4 | |
Linux Kernel | =2.6.20 | |
Linux Kernel | =2.6.20.1 | |
Microsoft Windows XP | ||
Oracle Solaris and Zettabyte File System (ZFS) | ||
IBM DB2 Universal Database | =8.0 | |
IBM DB2 Universal Database | =8.1 | |
IBM DB2 Universal Database | =8.1.4 | |
IBM DB2 Universal Database | =8.1.5 | |
IBM DB2 Universal Database | =8.1.6 | |
IBM DB2 Universal Database | =8.1.6c | |
IBM DB2 Universal Database | =8.1.7 | |
IBM DB2 Universal Database | =8.1.7b | |
IBM DB2 Universal Database | =8.1.8 | |
IBM DB2 Universal Database | =8.1.8a | |
IBM DB2 Universal Database | =8.1.9 | |
IBM DB2 Universal Database | =8.1.9a | |
IBM DB2 Universal Database | =8.10 | |
IBM DB2 Universal Database | =8.12 | |
IBM DB2 Universal Database | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-1086 is considered medium due to its potential for local user exploitation.
To fix CVE-2007-1086, upgrade IBM DB2 to version 8.1 FixPak 15 or 9.1 Fix Pack 2 or later.
CVE-2007-1086 affects IBM DB2 versions prior to 8.1 FixPak 15 and 9.1 before Fix Pack 2.
Local users of IBM DB2 versions prior to the mentioned fixes are mainly affected by CVE-2007-1086.
CVE-2007-1086 is a local privilege escalation vulnerability due to unsafe file access in IBM DB2.