CVE-2015-1883: Infoleak
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read certain administrative files via crafted use of an automated-maintenance policy stored procedure.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1883?
CVE-2015-1883 has been classified with a medium severity, allowing authenticated users to access sensitive files.
How do I fix CVE-2015-1883?
To mitigate CVE-2015-1883, upgrade IBM DB2 to the latest versions above the specified thresholds in its documentation.
What products are affected by CVE-2015-1883?
CVE-2015-1883 affects IBM DB2 versions 9.7, 9.8, 10.1, and 10.5 across Linux, UNIX, and Windows platforms.
Can CVE-2015-1883 be exploited remotely?
Yes, CVE-2015-1883 can be exploited by remote authenticated users who can execute specific stored procedures.
What types of files can be accessed due to CVE-2015-1883?
CVE-2015-1883 allows unauthorized reading of certain administrative files through crafted procedures.