PT-2012-2804 · Ibm · Ibm Db2
Martin Rakhmanov
·
Publicado
2012-03-20
·
Atualizado
2017-09-19
·
CVE-2012-0709
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4
Description
The issue allows remote authenticated users to bypass intended restrictions on viewing table data. This is achieved by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements, which are not properly checked.
Recommendations
For IBM DB2 version 9.5 before FP9, update to FP9 or later.
For IBM DB2 versions 9.7 through FP5, update to FP6 or later.
For IBM DB2 versions 9.8 through FP4, update to FP5 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Db2