MEDIUM
Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile
Published Oct 6, 2007
4.3
MEDIUMCVSS 2.0
EPSS 1.08%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.