4

CVE-2012-0709

IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 9.5
Ibm ≫ Db2 Version 9.5 Update fp1
Ibm ≫ Db2 Version 9.5 Update fp2
Ibm ≫ Db2 Version 9.5 Update fp2a
Ibm ≫ Db2 Version 9.5 Update fp3
Ibm ≫ Db2 Version 9.5 Update fp3a
Ibm ≫ Db2 Version 9.5 Update fp3b
Ibm ≫ Db2 Version 9.5 Update fp4
Ibm ≫ Db2 Version 9.5 Update fp4a
Ibm ≫ Db2 Version 9.5 Update fp5
Ibm ≫ Db2 Version 9.5 Update fp6
Ibm ≫ Db2 Version 9.5 Update fp6a
Ibm ≫ Db2 Version 9.5 Update fp7
Ibm ≫ Db2 Version 9.5 Update fp8
Ibm ≫ Db2 Version 9.7
Ibm ≫ Db2 Version 9.7 Update fp1
Ibm ≫ Db2 Version 9.7 Update fp2
Ibm ≫ Db2 Version 9.7 Update fp3
Ibm ≫ Db2 Version 9.7 Update fp3a
Ibm ≫ Db2 Version 9.7 Update fp4
Ibm ≫ Db2 Version 9.7 Update fp5
Ibm ≫ Db2 Version 9.8
Ibm ≫ Db2 Version 9.8 Update fp3
Ibm ≫ Db2 Version 9.8 Update fp4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.81% 0.764
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www-01.ibm.com/support/docview.wss?uid=swg1IC81387
http://www-01.ibm.com/support/docview.wss?uid=swg1IC81390
http://www-01.ibm.com/support/docview.wss?uid=swg1IC81836
http://www-01.ibm.com/support/docview.wss?uid=swg21588100
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/73493
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15004