« Volver al listado

CVE-2007-3337

Estado: ModificadaBaja (2.1)—

wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3337",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-22T18:30:00.000",
  "references": [
    {
      "url": "http://osvdb.org/37485",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25756",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25775",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-ingres-file-truncation/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/472200/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24585",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2288",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2290",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37485",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25756",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25775",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-ingres-file-truncation/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/472200/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24585",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2288",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2290",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file."
    },
    {
      "lang": "es",
      "value": "El inicio (wakeup) en la base de datos Ingres server 2006 9.0.4, r3, 2.6 y 2.5, tal y como se usa en los productos CA (Computer Associates), permite a usuarios locales truncar ficheros de su elección mediante un ataque symlink (de enlaces simbólicos) en el fichero alarmwkp.def."
    }
  ],
  "lastModified": "2026-06-16T22:41:47.587",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ingres:database_server:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D23E67C-E964-4571-B6FA-DCC910FD2A7C"
            },
            {
              "criteria": "cpe:2.3:a:ingres:database_server:2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0D77591-A8B7-4BAE-9761-CEB5A739A9E1"
            },
            {
              "criteria": "cpe:2.3:a:ingres:database_server:9.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFE10403-BEB4-4A63-BC0D-CC5803584F5E"
            },
            {
              "criteria": "cpe:2.3:a:ingres:database_server:r3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01A77427-8C8D-4ABD-8502-F40D704B5F8A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}