27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote database server is vulnerable to multiple attack vectors.\n\nFor<br />

your information, the observed version of IBM DB2 is %L\n\nVersions of IBM DB2 9.1<br />

earlier than Fix Pack 10 are potentially affected by multiple vulnerabilities :\n\n - Multiple<br />

buffer overflow vulnerabilities exist in the DB2 Administrative Service (DAS) which could<br />

lead to a denial-of-service, or the execution of arbitrary code. (IC69986, IC71203)\n\n -<br />

Users continue to have privilege to execute a non-DDL statement after their DBADM<br />

authority has been revoked. (IC66811)\nIAVB Reference : 2011-B-0013\nSTIG Finding<br />

Severity : Category I<br />

Solution: Upgrade to IBM DB2 9.1 Fix Pack 10 or later.<br />

CVE-2010-3731<br />

DB2 9.5 < Fix Pack 7 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5750 FAMILY: Database RISK: HIGH NESSUS ID:51841<br />

Description: Synopsis :\n\nThe remote database server is vulnerable to multiple attack vectors.\n\nFor<br />

your information, the observed version of IBM DB2 is %L\n\nVersions of IBM DB2 9.5<br />

earlier than Fix Pack 7 are potentially affected by multiple issues :\n\n - A buffer overflow<br />

vulnerability exists in the DB2 Administrative Service (DAS). (IC72028)\n\n - It is possible<br />

to update statistics for tables without appropriate privileges. (IC71413)\n\n - It is possible<br />

for a user to execute a non-DDL statement after role memebership has been revoked from<br />

its group. (IC71263)\nIAVB Reference : 2011-B-0013\nSTIG Finding Severity : Category I<br />

Solution: Upgrade to IBM DB2 9.5 Fix Pack 7 or later.<br />

CVE-2011-1847<br />

DB2 9.7 < Fix Pack 3 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5751 FAMILY: Database RISK: HIGH NESSUS ID:50451<br />

Description: Synopsis :\n\nThe remote database server is vulnerable to multiple attack vectors.\n\nFor<br />

your information, the observed version of IBM DB2 is %L\n\nVersions of IBM DB2 9.7<br />

earlier than Fix Pack 3 are potentially affected by multiple vulnerabilities :\n\n - When<br />

privileges on a database object are revoked from PUBLIC, the dependent functions are not<br />

marked INVALID. As a result, users with execute privilege on the function are still able to<br />

call it successfully. (IC68015)\n\n - If a compound SQL (compiled) statement has been<br />

issued by a user that is properly authorized, this is cached in the dynamic SQL cache. Once<br />

cached, this same query can be executed by an user if that user has the proper authority.<br />

(IC70406)\n\n - Multiple buffer overflow vulnerabilities exist in the DB2 Administrative<br />

Server (DAS). (IC70539, IC72029)\nIAVB Reference : 2011-B-0013\nSTIG Finding<br />

Severity : Category I<br />

Solution: Upgrade to IBM DB2 9.7 Fix Pack 3 or later.<br />

CVE-2011-0731<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Exim < 4.74 Local Privilege Escalation Vulnerability<br />

Family Internet Services 1559

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!