CVE-2017-1677
22.03.2018, 12:29
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | db2 | 9.7 |
ibm | db2 | 10.1 |
ibm | db2 | 10.5 |
ibm | db2 | 11.1 |
ibm | db2 | 9.7 |
ibm | db2 | 10.1 |
ibm | db2 | 10.5 |
ibm | db2 | 11.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References