5

CVE-2009-1239

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmDb2 Updatefp6a Version <= 9.1
IbmDb2 Version9.1
IbmDb2 Version9.1 Editionconnect_server
IbmDb2 Version9.1 Editionenterprise_server
IbmDb2 Version9.1 Editionexpress_server
IbmDb2 Version9.1 Editionpersonal
IbmDb2 Version9.1 Editionworkgroup_server
IbmDb2 Version9.1 Updatefp1
IbmDb2 Version9.1 Updatefp1 Editionunix
IbmDb2 Version9.1 Updatefp1 Editionwindows
IbmDb2 Version9.1 Updatefp2
IbmDb2 Version9.1 Updatefp3
IbmDb2 Version9.1 Updatefp3a
IbmDb2 Version9.1 Updatefp4
IbmDb2 Version9.1 Updatefp4a
IbmDb2 Version9.1 Updatefp5
IbmDb2 Version9.1 Updatefp6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.503
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.