First published: Wed Jun 03 2009(Updated: )
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =8.0-fp1 | |
IBM Db2 | =8.0-fp10 | |
IBM Db2 | =8.0-fp11 | |
IBM Db2 | =8.0-fp12 | |
IBM Db2 | =8.0-fp13 | |
IBM Db2 | =8.0-fp14 | |
IBM Db2 | =8.0-fp15 | |
IBM Db2 | =8.0-fp16 | |
IBM Db2 | =9.1-fp1 | |
IBM Db2 | =9.1-fp2 | |
IBM Db2 | =9.1-fp3 | |
IBM Db2 | =9.1-fp3a | |
IBM Db2 | =9.1-fp4 | |
IBM Db2 | =9.1-fp4a | |
IBM Db2 | =9.5-fp1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6820 has an unknown impact and attack vectors associated with the db2fmp process running with OS privileges.
To mitigate CVE-2008-6820, upgrade the IBM DB2 versions to the latest fix pack beyond the vulnerable versions.
CVE-2008-6820 affects IBM DB2 versions 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows.
The risks of CVE-2008-6820 include unauthorized access and privilege escalation due to the db2fmp process running with elevated OS privileges.
Yes, CVE-2008-6820 specifically impacts IBM DB2 on Microsoft Windows.