« Volver al listado

CVE-2008-7131

Estado: ModificadaMedia (6.8)—

Unspecified vulnerability in DB2 Monitoring Console 2.2.4 and earlier allows remote attackers to gain access to a database via a link to a victim who is already connected to the database.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-7131",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-08-31T10:30:01.280",
  "references": [
    {
      "url": "http://osvdb.org/43114",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29367",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/forum/forum.php?forum_id=797405",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/28253",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41212",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/43114",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29367",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/forum/forum.php?forum_id=797405",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/28253",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41212",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in DB2 Monitoring Console 2.2.4 and earlier allows remote attackers to gain access to a database via a link to a victim who is already connected to the database."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad no especificada en DB2 Monitoring Console v2.2.4 y anteriores, permite a atacantes remotos obtener acceso a una base de datos a través de un enlace a una víctima que en ese momento esté conectada a la base de datos."
    }
  ],
  "lastModified": "2026-06-16T23:03:40.547",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:peter_kohlmann:db2_monitoring_console:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EB11E08-D0FC-4079-A437-76839FE5C8DF",
              "versionEndIncluding": "2.2.24"
            },
            {
              "criteria": "cpe:2.3:a:peter_kohlmann:db2_monitoring_console:2.1.236:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16E6FA61-0C08-4B6A-8678-DEC944D8D8D2"
            },
            {
              "criteria": "cpe:2.3:a:peter_kohlmann:db2_monitoring_console:2.1.246:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2646C0A1-226E-4C58-89AD-74872EC3CAA9"
            },
            {
              "criteria": "cpe:2.3:a:peter_kohlmann:db2_monitoring_console:2.1.248:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BD7D741-38F6-4DFA-AFE7-14D0B398B38F"
            },
            {
              "criteria": "cpe:2.3:a:peter_kohlmann:db2_monitoring_console:2.1.251:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2312A554-036A-4DB5-B344-B6428A324052"
            },
            {
              "criteria": "cpe:2.3:a:peter_kohlmann:db2_monitoring_console:2.2.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65A94230-F13A-48EF-9382-069E5152F24D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}