Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM DB2 基本服务组件 本地敏感信息泄露漏洞
Vulnerability Description
IBM DB2是美国IBM公司的一套关系型数据库管理系统。该系统的执行环境主要有UNIX、Linux、IBM i、z/OS以及Windows服务器版本。 DB2 9.1.x中低于9.1.5的版本中基本组件存在敏感信息泄露漏洞。 在用户发送口令进行数据库连接后,DB2基本服务组件将口令以明文方式保留于内存中。 本地攻击者可以通过读取内存信息的方式,获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A