IBM DB2 Content Manager AllowedTrustedLogin privilege unspecified
| ibm-db2-allowedtrustedlogin-unspecified (41585) |
Description:
An unspecified vulnerability in IBM DB2 Content Manager related to the AllowedTrustedLogin privilege has an unknown impact and attack vector.
Platforms Affected:
- IBM, DB2 Content Manager 8.2 Fix Pack 10
- IBM, DB2 Content Manager 8.2 Fix Pack 9
- IBM, DB2 Content Manager 8.2 Fix Pack 1
- IBM, DB2 Content Manager 8.2 Fix Pack 2
- IBM, DB2 Content Manager 8.2 Fix Pack 3
- IBM, DB2 Content Manager 8.2 Fix Pack 4
- IBM, DB2 Content Manager 8.2 Fix Pack 5
- IBM, DB2 Content Manager 8.2 Fix Pack 6
- IBM, DB2 Content Manager 8.2 Fix Pack 7
- IBM, DB2 Content Manager 8.2 Fix Pack 8
- IBM, DB2 Content Manager 8.3 Fix Pack 8
- IBM, DB2 Content Manager 8.3
- IBM, DB2 Content Manager 8.3 Fix Pack 1
- IBM, DB2 Content Manager 8.3 Fix Pack 2
- IBM, DB2 Content Manager 8.3 Fix Pack 3
- IBM, DB2 Content Manager 8.3 Fix Pack 4
- IBM, DB2 Content Manager 8.3 Fix Pack 5
- IBM, DB2 Content Manager 8.3 Fix Pack 6
- IBM, DB2 Content Manager 8.3 Fix Pack 7
- IBM, DB2 Content Manager 8.3 Fix Pack 3a
Remedy:
Upgrade to the latest version of IBM DB2 Content Manager (8.3 Fix Pack 8 or later), available from the IBM Support & downloads Web site. See References.
Consequences:
Other
References:
- IBM Support & downloads Web site, DB2 Content Manager Version 8.3 Fix Pack 8 at http://publib.boulder.ibm.com/infocenter/cmgmt/v8r3m0/index.jsp?topic=/com.ibm.cmgmtreadmefp.doc/aparlist.htm.
- BID-28567: IBM DB2 Content Manager Unspecified Security Vulnerability
- CVE-2008-1681: Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privilege.
- FrSIRT/ADV-2008-1070: IBM DB2 Content Manager AllowedTrustedLogin Vulnerability
- SA29647: IBM DB2 Content Manager AllowedTrustedLogin Security Issue
Reported:
Apr 02, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
