CVE-2013-4033

CWE-2643 documents3 sources
Severity
4.6MEDIUM
EPSS
1.0%
top 23.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 28
Latest updateMay 17

Description

IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

NVDibm/db2_connect5 versions+4
NVDibm/db24 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-r55h-hjww-3r48: IBM DB2 and DB2 Connect 92022-05-17
CVEList
CVE-2013-4033: IBM DB2 and DB2 Connect 92013-08-28
CVE-2013-4033 (MEDIUM CVSS 4.6) | IBM DB2 and DB2 Connect 9.7 through | cvebase.io