CVE-2016-5995
Last modified
CVE-2016-5995 is a vulnerability of currently unknown severity. Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 | 9.7 |
| Ibm | Db2 | 9.7.0.1 |
| Ibm | Db2 | 9.7.0.2 |
| Ibm | Db2 | 9.7.0.3 |
| Ibm | Db2 | 9.7.0.4 |
| Ibm | Db2 | 9.7.0.5 |
| Ibm | Db2 | 9.7.0.6 |
| Ibm | Db2 | 9.7.0.7 |
| Ibm | Db2 | 9.7.0.8 |
| Ibm | Db2 | 9.7.0.9 |
| Ibm | Db2 | 9.7.0.10 |
| Ibm | Db2 | 9.7.0.11 |
| Ibm | Db2 | 10.1 |
| Ibm | Db2 | 10.1.0.1 |
| Ibm | Db2 | 10.1.0.2 |
| Ibm | Db2 | 10.1.0.3 |
| Ibm | Db2 | 10.1.0.4 |
| Ibm | Db2 | 10.1.0.5 |
| Ibm | Db2 | 10.5 |
| Ibm | Db2 | 10.5.0.1 |
| Ibm | Db2 | 10.5.0.2 |
| Ibm | Db2 | 10.5.0.3 |
| Ibm | Db2 | 10.5.0.4 |
| Ibm | Db2 | 10.5.0.5 |
| Ibm | Db2 | 10.5.0.6 |
| Ibm | Db2 | 10.5.0.7 |
| Ibm | Db2 | 11.1.0.0 |
| Ibm | Db2 Connect | 9.7 |
| Ibm | Db2 Connect | 9.7.0.1 |
| Ibm | Db2 Connect | 9.7.0.2 |
| Ibm | Db2 Connect | 9.7.0.3 |
| Ibm | Db2 Connect | 9.7.0.4 |
| Ibm | Db2 Connect | 9.7.0.5 |
| Ibm | Db2 Connect | 9.7.0.6 |
| Ibm | Db2 Connect | 9.7.0.7 |
| Ibm | Db2 Connect | 9.7.0.8 |
| Ibm | Db2 Connect | 9.7.0.9 |
| Ibm | Db2 Connect | 9.7.0.10 |
| Ibm | Db2 Connect | 9.7.0.11 |
| Ibm | Db2 Connect | 10.1 |
| Ibm | Db2 Connect | 10.1.0.1 |
| Ibm | Db2 Connect | 10.1.0.2 |
| Ibm | Db2 Connect | 10.1.0.3 |
| Ibm | Db2 Connect | 10.1.0.4 |
| Ibm | Db2 Connect | 10.1.0.5 |
| Ibm | Db2 Connect | 10.5 |
| Ibm | Db2 Connect | 10.5.0.1 |
| Ibm | Db2 Connect | 10.5.0.2 |
| Ibm | Db2 Connect | 10.5.0.3 |
| Ibm | Db2 Connect | 10.5.0.4 |
Showing 50 of 54 affected configurations. See NVD for the full list.
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT16921Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT17010Permissions Required
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT17011Permissions Required
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT17012Permissions Required
- http://www-01.ibm.com/support/docview.wss?uid=swg21990061Patch, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT16921Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT17010Permissions Required
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT17011Permissions Required
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT17012Permissions Required
- http://www-01.ibm.com/support/docview.wss?uid=swg21990061Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-5995?
How severe is CVE-2016-5995?
How do I fix CVE-2016-5995?
Are you affected by CVE-2016-5995?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
