CVE-2007-1089: High severity Linux Linux kernel vulnerability
Published Feb 23, 2007
·Updated
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
Affected Software
18 affected components
Linux Linux kernel=2.6.18.0
Linux Linux kernel=2.6.18.1
Linux Linux kernel=2.6.18.2
Linux Linux kernel=2.6.18.3
Linux Linux kernel=2.6.18.4
Linux Linux kernel=2.6.18.5
Linux Linux kernel=2.6.18.6
Linux Linux kernel=2.6.18.7
Linux Linux kernel=2.6.19
Linux Linux kernel=2.6.19.1
Linux Linux kernel=2.6.19.2
Linux Linux kernel=2.6.19.3
Linux Linux kernel=2.6.19.4
Linux Linux kernel=2.6.20
Linux Linux kernel=2.6.20.1
Microsoft Windows XP
IBM DB2 Universal Database<=9.1
IBM DB2 Universal Database=9.1-ga
Remediation
Patch Available
Patch Available
Event History
Feb 23, 2007
CVE Published
10:28 PM
Data Sourced
10:28 PM
DescriptionWeaknessAffected Software
Feb 24, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1089?
CVE-2007-1089 has a moderate severity level as it allows unauthorized updates and deletions by local users with select privileges.
2
How do I fix CVE-2007-1089?
To fix CVE-2007-1089, ensure that you upgrade to a patched version of IBM DB2 Universal Database that addresses this vulnerability.
3
Who is affected by CVE-2007-1089?
CVE-2007-1089 affects users of IBM DB2 Universal Database versions 9.1 GA through 9.1 FP1.
4
What type of vulnerability is CVE-2007-1089?
CVE-2007-1089 is a local privilege escalation vulnerability that allows unauthorized SQL command execution.
5
When was CVE-2007-1089 discovered?
CVE-2007-1089 was publicly disclosed in 2007.