CVE-2014-4805: Infoleak
Published Sep 4, 2014
·Updated
IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.
Affected Software
7 affected components
IBM DB2=10.5
IBM DB2=10.5.0.1
IBM DB2=10.5.0.2
IBM DB2=10.5.0.3
IBM DB2=10.5.0.3-a
IBM AIX
Linux Linux kernel
Remediation
Patch Available
Event History
Sep 4, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4805?
CVE-2014-4805 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2014-4805?
To fix CVE-2014-4805, apply the latest fix pack for IBM DB2 or implement access controls to restrict file access during LOAD operations.
3
Who is affected by CVE-2014-4805?
CVE-2014-4805 affects IBM DB2 version 10.5 on Linux and AIX systems.
4
What type of information is exposed in CVE-2014-4805?
CVE-2014-4805 can potentially expose sensitive information stored in temporary files during the LOAD operations.
5
Is CVE-2014-4805 exploitable remotely?
CVE-2014-4805 is not remotely exploitable as it requires local access to the affected system.