CVE-2017-1297
CVE-2017-1297
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 1.5%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
26 Jun 2017Public PoC
27 Jun 2017Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
Affected products
IBM · DB2 for Linux, UNIX and Windowspublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/42260/unverifiedexploitdbwww.exploit-db.com/exploits/42260unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →