CVE-2008-6820: Critical severity ibm db2 universal database vulnerability
Published Jun 3, 2009
·Updated
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
Affected Software
16 affected components
IBM db2=8.0-fp1
IBM db2=8.0-fp10
IBM db2=8.0-fp11
IBM db2=8.0-fp12
IBM db2=8.0-fp13
IBM db2=8.0-fp14
IBM db2=8.0-fp15
IBM db2=8.0-fp16
IBM db2=9.1-fp1
IBM db2=9.1-fp2
IBM db2=9.1-fp3
IBM db2=9.1-fp3a
IBM db2=9.1-fp4
IBM db2=9.1-fp4a
IBM db2=9.5-fp1
Microsoft Windows
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jun 3, 2009
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
Description
Data Sourced
09:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6820?
CVE-2008-6820 has an unknown impact and attack vectors associated with the db2fmp process running with OS privileges.
2
How do I fix CVE-2008-6820?
To mitigate CVE-2008-6820, upgrade the IBM DB2 versions to the latest fix pack beyond the vulnerable versions.
3
What products are affected by CVE-2008-6820?
CVE-2008-6820 affects IBM DB2 versions 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows.
4
What are the potential risks of CVE-2008-6820?
The risks of CVE-2008-6820 include unauthorized access and privilege escalation due to the db2fmp process running with elevated OS privileges.
5
Is CVE-2008-6820 specific to any operating system?
Yes, CVE-2008-6820 specifically impacts IBM DB2 on Microsoft Windows.