CVE-2008-3857
28.08.2008, 17:41
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | db2_universal_database | 9.1 |
ibm | db2_universal_database | 9.1 |
ibm | db2_universal_database | 9.1 |
ibm | db2_universal_database | 9.1 |
ibm | db2_universal_database | 9.1 |
ibm | db2_universal_database | 9.1:fp2 |
ibm | db2_universal_database | 9.1:fp2 |
ibm | db2_universal_database | 9.1:fp2 |
ibm | db2_universal_database | 9.1:fp2 |
ibm | db2_universal_database | 9.1:fp2 |
ibm | db2_universal_database | 9.1:fp3 |
ibm | db2_universal_database | 9.1:fp3 |
ibm | db2_universal_database | 9.1:fp3 |
ibm | db2_universal_database | 9.1:fp3 |
ibm | db2_universal_database | 9.1:fp3 |
ibm | db2_universal_database | 9.1:fp4 |
ibm | db2_universal_database | 9.1:fp4 |
ibm | db2_universal_database | 9.1:fp4 |
ibm | db2_universal_database | 9.1:fp4a |
ibm | db2_universal_database | 9.1:fp4a |
ibm | db2_universal_database | 9.1:fp4a |
ibm | db2_universal_database | 9.1:fp4a |
ibm | db2_universal_database | 9.1:fp4a |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References