CVE-2014-8910

MEDIUM

Description

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement.

References

http://www-01.ibm.com/support/docview.wss?uid=swg1IT06353

http://www-01.ibm.com/support/docview.wss?uid=swg1IT06354

http://www-01.ibm.com/support/docview.wss?uid=swg1IT06355

http://www-01.ibm.com/support/docview.wss?uid=swg1IT06356

http://www-01.ibm.com/support/docview.wss?uid=swg21697988

http://www.securityfocus.com/bid/75949

http://www.securitytracker.com/id/1032883

Details

Source: MITRE

Published: 2015-07-20

Updated: 2017-09-22

Type: CWE-74

Risk Information

CVSS v2.0

Base Score: 4

Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM