CVE-2012-1796: High severity IBM DB2 vulnerability
Published Mar 20, 2012
·Updated
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
Affected Software
18 affected components
IBM DB2=9.5
IBM DB2=9.5-fp1
IBM DB2=9.5-fp2
IBM DB2=9.5-fp2a
IBM DB2=9.5-fp3
IBM DB2=9.5-fp3a
IBM DB2=9.5-fp3b
IBM DB2=9.5-fp4
IBM DB2=9.5-fp4a
IBM DB2=9.5-fp5
IBM DB2=9.5-fp6
IBM DB2=9.5-fp6a
IBM DB2=9.5-fp7
IBM DB2=9.5-fp8
HP HP-UX
IBM AIX
Linux Linux kernel
Sun SunOS
Event History
Mar 20, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1796?
CVE-2012-1796 is considered a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2012-1796?
To remediate CVE-2012-1796, upgrade your IBM DB2 to version 9.5 Fix Pack 9 or later.
3
Who is affected by CVE-2012-1796?
CVE-2012-1796 affects all local users on systems running vulnerable versions of IBM DB2 9.5 prior to Fix Pack 9.
4
What type of vulnerability is CVE-2012-1796?
CVE-2012-1796 is a local privilege escalation vulnerability that allows users to gain elevated access.
5
Can CVE-2012-1796 be exploited remotely?
CVE-2012-1796 cannot be exploited remotely as it requires local user access to the vulnerable system.