CVE-2007-5664: Medium severity IBM DB2 Universal Database vulnerability
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5664?
CVE-2007-5664 has a medium severity rating due to its potential for local file overwriting through symlink attacks.
How do I fix CVE-2007-5664?
To fix CVE-2007-5664, apply the appropriate Fix Pack updates for your version of IBM DB2 Universal Database.
Who is affected by CVE-2007-5664?
CVE-2007-5664 affects local users of IBM DB2 Universal Database versions 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16.
What type of attack is demonstrated by CVE-2007-5664?
CVE-2007-5664 demonstrates a symlink attack that allows local users to overwrite arbitrary files.
What systems are vulnerable to CVE-2007-5664?
Systems running IBM DB2 Universal Database versions 8.0, 9.1, and 9.5 prior to their respective fixes are vulnerable to CVE-2007-5664.