PT-2012-2804 · Ibm · Ibm Db2
Martin Rakhmanov
·
Published
2012-03-20
·
Updated
2017-09-19
·
CVE-2012-0709
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4
Description
The issue allows remote authenticated users to bypass intended restrictions on viewing table data. This is achieved by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements, which are not properly checked.
Recommendations
For IBM DB2 version 9.5 before FP9, update to FP9 or later.
For IBM DB2 versions 9.7 through FP5, update to FP6 or later.
For IBM DB2 versions 9.8 through FP4, update to FP5 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Db2