IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www-1.ibm.com/support/docview.wss?uid=swg21255607 | |
http://osvdb.org/41017 | vdb entry |
http://www.vupen.com/english/advisories/2007/3867 | vdb entry |
http://www.securityfocus.com/bid/26450 | vdb entry patch |
http://www-1.ibm.com/support/docview.wss?uid=swg1JR26989 | vendor advisory |
http://secunia.com/advisories/27667 | third party advisory patch vendor advisory |