5

CVE-2009-1239

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Update fp6a Version <= 9.1
Ibm ≫ Db2 Version 9.1
Ibm ≫ Db2 Version 9.1 Edition connect_server
Ibm ≫ Db2 Version 9.1 Edition enterprise_server
Ibm ≫ Db2 Version 9.1 Edition express_server
Ibm ≫ Db2 Version 9.1 Edition personal
Ibm ≫ Db2 Version 9.1 Edition workgroup_server
Ibm ≫ Db2 Version 9.1 Update fp1
Ibm ≫ Db2 Version 9.1 Update fp1 Edition unix
Ibm ≫ Db2 Version 9.1 Update fp1 Edition windows
Ibm ≫ Db2 Version 9.1 Update fp2
Ibm ≫ Db2 Version 9.1 Update fp3
Ibm ≫ Db2 Version 9.1 Update fp3a
Ibm ≫ Db2 Version 9.1 Update fp4
Ibm ≫ Db2 Version 9.1 Update fp4a
Ibm ≫ Db2 Version 9.1 Update fp5
Ibm ≫ Db2 Version 9.1 Update fp6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.596
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www-01.ibm.com/support/docview.wss?uid=swg1JR31886
Patch
http://www-01.ibm.com/support/docview.wss?uid=swg21381257
Patch
Vendor Advisory
http://www.vupen.com/english/advisories/2009/0912
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49864