VulnerabilityModified
CVE-2009-3472
IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
MEDIUM 6.5EPSS 2.02%
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/db2
- Source
- cve@mitre.org
References
- http://osvdb.org/58478
- http://secunia.com/advisories/36890Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50074
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50078
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50079
- http://www-01.ibm.com/support/docview.wss?uid=swg21386689Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21403619
- http://www.securityfocus.com/bid/36540
- http://osvdb.org/58478
- http://secunia.com/advisories/36890Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50074
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50078
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50079
- http://www-01.ibm.com/support/docview.wss?uid=swg21386689Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21403619
- http://www.securityfocus.com/bid/36540
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.