CVE-2014-0907
Last modified
CVE-2014-0907 is a vulnerability of currently unknown severity. Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 | 9.5 |
| Ibm | Db2 | 9.7 |
| Ibm | Db2 | 9.7.0.1 |
| Ibm | Db2 | 9.7.0.2 |
| Ibm | Db2 | 9.7.0.3 |
| Ibm | Db2 | 9.7.0.4 |
| Ibm | Db2 | 9.7.0.5 |
| Ibm | Db2 | 9.7.0.6 |
| Ibm | Db2 | 9.7.0.7 |
| Ibm | Db2 | 9.7.0.8 |
| Ibm | Db2 | 9.7.0.9 |
| Ibm | Db2 | 10.1 |
| Ibm | Db2 | 10.1.0.1 |
| Ibm | Db2 | 10.1.0.2 |
| Ibm | Db2 | 10.1.0.3 |
| Ibm | Db2 | 10.5 |
| Ibm | Db2 | 10.5.0.1 |
| Ibm | Db2 | 10.5.0.2 |
References
- http://www.ibm.com/support/docview.wss?uid=swg21610582#4Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21672100Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21610582#4Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21672100Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0907?
How severe is CVE-2014-0907?
How do I fix CVE-2014-0907?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-0899ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when…
- CVE-2014-0900The Device Administrator code in Android before 4.4.1_r1 mig…
- CVE-2014-0901Cross-site scripting (XSS) vulnerability in the Social Rende…
- CVE-2014-0904The update process in IBM Security AppScan Standard 7.9 thro…
- CVE-2014-0905IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set th…
- CVE-2014-0906The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9…
- CVE-2014-0908The User Attribute implementation in IBM Business Process Ma…
- CVE-2014-0909The Administration and Reporting Tool in IBM Rational Licens…
- CVE-2014-0910Cross-site scripting (XSS) vulnerability in IBM WebSphere Po…
- CVE-2014-0911inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x bef…
- CVE-2014-0912IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Ga…
- CVE-2014-0913Cross-site scripting (XSS) vulnerability in IBM iNotes and D…
Are you affected by CVE-2014-0907?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
