6.4

CVE-2010-3739

The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.

Data is provided by the National Vulnerability Database (NVD)
IbmDb2 Universal Database Updatefp6 Version <= 9.5
IbmDb2 Universal Database Version9.5
IbmDb2 Universal Database Version9.5 Updatefp1
IbmDb2 Universal Database Version9.5 Updatefp2
IbmDb2 Universal Database Version9.5 Updatefp2a
IbmDb2 Universal Database Version9.5 Updatefp3
IbmDb2 Universal Database Version9.5 Updatefp3a
IbmDb2 Universal Database Version9.5 Updatefp3b
IbmDb2 Universal Database Version9.5 Updatefp4
IbmDb2 Universal Database Version9.5 Updatefp4a
IbmDb2 Universal Database Version9.5 Updatefp5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.45
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.