CVE-2007-1089
published 2007-02-23CVE-2007-1089: IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.30%
22.4th percentile
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2_universal_database | <= 9.1 | — |
| ibm | db2_universal_database | <= 8.0 | — |
| ibm | db2_universal_database | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-433x-hjc8-g7w7: IBM DB2 Universal Database (UDB) 9
ghsa_unreviewed·2022-05-01
CVE-2007-1089 [HIGH] GHSA-433x-hjc8-g7w7: IBM DB2 Universal Database (UDB) 9
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
GHSA
GHSA-78qc-jhj6-3x6x: IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-4418 [HIGH] GHSA-78qc-jhj6-3x6x: IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have
IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE: this issue is probably related to CVE-2007-1089, but this is uncertain due to lack of details.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/24283http://www-1.ibm.com/support/docview.wss?uid=swg1JR25941http://www.attrition.org/pipermail/vim/2007-August/001765.htmlhttp://www.vupen.com/english/advisories/2007/0721http://secunia.com/advisories/24283http://www-1.ibm.com/support/docview.wss?uid=swg1JR25941http://www.attrition.org/pipermail/vim/2007-August/001765.htmlhttp://www.vupen.com/english/advisories/2007/0721
2007-02-23
Published