10

CVE-2009-3473

IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 9.1 Update fp1
Ibm ≫ Db2 Version 9.1 Update fp2
Ibm ≫ Db2 Version 9.1 Update fp3
Ibm ≫ Db2 Version 9.1 Update fp4
Ibm ≫ Db2 Version 9.1 Update fp5
Ibm ≫ Db2 Version 9.1 Update fp6
Ibm ≫ Db2 Version 9.1 Update fp7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.02% 0.792
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/36540
http://secunia.com/advisories/36890
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21403619
http://osvdb.org/58479
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55883