2.6

CVE-2009-1905

The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmDb2 Updatefp16 Version <= 8.0
   IbmDb2 Updatefp16 Version <= 8.0
   IbmDb2 Updatefp16 Version <= 8.0
IbmDb2 Updatefp4 Version <= 9.1
   IbmDb2 Updatefp4 Version <= 9.1
   IbmDb2 Updatefp4 Version <= 9.1
IbmDb2 Updatefp1 Version <= 9.5
   IbmDb2 Updatefp1 Version <= 9.5
   IbmDb2 Updatefp1 Version <= 9.5
IbmDb2 Version8.0 Updatefix_pack15
   IbmDb2 Version8.0 Updatefix_pack15
   IbmDb2 Version8.0 Updatefix_pack15
IbmDb2 Version8.0 Updatefp1
   IbmDb2 Version8.0 Updatefp1
   IbmDb2 Version8.0 Updatefp1
IbmDb2 Version8.0 Updatefp10
   IbmDb2 Version8.0 Updatefp10
   IbmDb2 Version8.0 Updatefp10
IbmDb2 Version8.0 Updatefp11
   IbmDb2 Version8.0 Updatefp11
   IbmDb2 Version8.0 Updatefp11
IbmDb2 Version8.0 Updatefp12
   IbmDb2 Version8.0 Updatefp12
   IbmDb2 Version8.0 Updatefp12
IbmDb2 Version8.0 Updatefp13
   IbmDb2 Version8.0 Updatefp13
   IbmDb2 Version8.0 Updatefp13
IbmDb2 Version8.0 Updatefp14
   IbmDb2 Version8.0 Updatefp14
   IbmDb2 Version8.0 Updatefp14
IbmDb2 Version8.0 Updatefp15
   IbmDb2 Version8.0 Updatefp15
   IbmDb2 Version8.0 Updatefp15
IbmDb2 Version9.1 Updatefp1
   IbmDb2 Version9.1 Updatefp1
   IbmDb2 Version9.1 Updatefp1
IbmDb2 Version9.1 Updatefp2
   IbmDb2 Version9.1 Updatefp2
   IbmDb2 Version9.1 Updatefp2
IbmDb2 Version9.1 Updatefp3
   IbmDb2 Version9.1 Updatefp3
   IbmDb2 Version9.1 Updatefp3
IbmDb2 Version9.1 Updatefp3a
   IbmDb2 Version9.1 Updatefp3a
   IbmDb2 Version9.1 Updatefp3a
IbmDb2 Version9.1 Updatefp4a
   IbmDb2 Version9.1 Updatefp4a
   IbmDb2 Version9.1 Updatefp4a
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.631
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.