CVE-2009-3471
published 2009-09-29CVE-2009-3471: IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.38%
81.9th percentile
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84rv-5h5j-48fx: IBM DB2 9
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2010-3474 [HIGH] GHSA-84rv-5h5j-48fx: IBM DB2 9
IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
GHSA
GHSA-pq7c-3frg-72hg: IBM DB2 8 before FP18, 9
ghsa_unreviewed·2022-05-03
CVE-2009-3471 [HIGH] GHSA-pq7c-3frg-72hg: IBM DB2 8 before FP18, 9
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
No detection rules found.
No public exploits indexed.
ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXThttp://osvdb.org/58477http://secunia.com/advisories/36890http://www-01.ibm.com/support/docview.wss?uid=swg1IC63548http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46658http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46773http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46774http://www-01.ibm.com/support/docview.wss?uid=swg21386689http://www-01.ibm.com/support/docview.wss?uid=swg21403619http://www-01.ibm.com/support/docview.wss?uid=swg21426108http://www-01.ibm.com/support/docview.wss?uid=swg21432298http://www.securityfocus.com/bid/36540ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXThttp://osvdb.org/58477http://secunia.com/advisories/36890http://www-01.ibm.com/support/docview.wss?uid=swg1IC63548http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46658http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46773http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46774http://www-01.ibm.com/support/docview.wss?uid=swg21386689http://www-01.ibm.com/support/docview.wss?uid=swg21403619http://www-01.ibm.com/support/docview.wss?uid=swg21426108http://www-01.ibm.com/support/docview.wss?uid=swg21432298http://www.securityfocus.com/bid/36540
2009-09-29
Published