CVE-2009-4438IBM DB2 vulnerability

CWE-2643 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
1.0%
top 22.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 28
Latest updateMay 3

Description

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDibm/db29.1, 9.5, 9.7+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4w48-3xmg-2w3m: The Query Compiler, Rewrite, and Optimizer component in IBM DB2 92022-05-03
CVEList
CVE-2009-4438: The Query Compiler, Rewrite, and Optimizer component in IBM DB2 92009-12-28
CVE-2009-4438 — IBM DB2 vulnerability | cvebase