The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-10-22 11:00
Updated : 2017-08-07 18:32
NVD link : CVE-2008-4693
Mitre link : CVE-2008-4693
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
ibm
- db2