PT-2009-6456 · Ibm · Ibm Db2

Published

2009-12-16

·

Updated

2010-06-29

·

CVE-2009-4333

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM DB2 version 9.5 before FP5
Description The issue allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
Recommendations For IBM DB2 version 9.5 before FP5, update to FP5 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4333

Affected Products

Ibm Db2