CVE-2017-1677
Last modified
CVE-2017-1677 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.
Metrics
CVSS:3.0/A:H/AC:H/AV:L/C:H/I:H/PR:N/S:U/UI:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 | 9.7 |
| Ibm | Db2 | 10.1 |
| Ibm | Db2 | 10.5 |
| Ibm | Db2 | 11.1 |
References
- http://www.ibm.com/support/docview.wss?uid=swg22012896Vendor Advisory
- http://www.securityfocus.com/bid/103422Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/133999VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22012896Vendor Advisory
- http://www.securityfocus.com/bid/103422Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/133999VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1677?
How severe is CVE-2017-1677?
How do I fix CVE-2017-1677?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16764An exploitable vulnerability exists in the YAML parsing func…9.8
- CVE-2017-16765XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin…6.1
- CVE-2017-16766An improper access control vulnerability in synodsmnotify in…
- CVE-2017-16767Cross-site scripting (XSS) vulnerability in User Profile in …
- CVE-2017-16768Cross-site scripting (XSS) vulnerability in User Policy edit…
- CVE-2017-16769Exposure of private information vulnerability in Photo Viewe…
- CVE-2017-16770File and directory information exposure vulnerability in SYN…
- CVE-2017-16771Cross-site scripting (XSS) vulnerability in Log Viewer in Sy…
- CVE-2017-16772Improper input validation vulnerability in SYNOPHOTO_Flickr_…
- CVE-2017-16773Improper authorization vulnerability in Highlight Preview in…6.5
- CVE-2017-16774Cross-site scripting (XSS) vulnerability in SYNO.Core.Person…6.5
- CVE-2017-16775Improper restriction of rendered UI layers or frames vulnera…7.1
Are you affected by CVE-2017-1677?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
