7.5

CVE-2009-4333

The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 9.5
Ibm ≫ Db2 Version 9.5 Update fp1
Ibm ≫ Db2 Version 9.5 Update fp2
Ibm ≫ Db2 Version 9.5 Update fp2a
Ibm ≫ Db2 Version 9.5 Update fp3
Ibm ≫ Db2 Version 9.5 Update fp3a
Ibm ≫ Db2 Version 9.5 Update fp3b
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.33% 0.674
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
http://www-01.ibm.com/support/docview.wss?uid=swg21293566
Patch
http://secunia.com/advisories/37759
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21412902
Vendor Advisory
http://www.securityfocus.com/bid/37332
http://www.vupen.com/english/advisories/2009/3520
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ38819
Vendor Advisory