CVE-2017-1150: Low severity IBM DB2 vulnerability
Published Mar 8, 2017
·Updated
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.
Affected Software
18 affected components
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=11.1
IBM DB2=11.1
IBM DB2=11.1
IBM DB2=11.1
IBM DB2=11.1
IBM DB2=11.1
Remediation
Patch Available
Event History
Mar 8, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-1150?
CVE-2017-1150 has been rated as a high severity vulnerability due to unauthorized access to sensitive data.
2
How do I fix CVE-2017-1150?
To fix CVE-2017-1150, ensure that you apply the appropriate security patches provided by IBM for DB2 versions 10.1, 10.5, and 11.1.
3
Who is affected by CVE-2017-1150?
CVE-2017-1150 affects users of IBM DB2 for Linux, UNIX, and Windows versions 10.1, 10.5, and 11.1.
4
What type of attack does CVE-2017-1150 enable?
CVE-2017-1150 enables authenticated attackers with specific table access to view data they should not access.
5
When was CVE-2017-1150 reported?
CVE-2017-1150 was reported as a security vulnerability in 2017.