CVE-2008-1705
Published Apr 9, 2008
Last updated 6 years ago
Overview
- Description
- Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) user name, (2) peer name, and possibly unspecified other fields.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-134
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:soliddb:06.00.1018:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "979423E3-2025-4EB2-B1C5-5C6B6A39B745" } ], "operator": "OR" } ] } ]