CVE-2009-4326
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection…
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/db2
- Source
- cve@mitre.org
References
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT
- http://secunia.com/advisories/37759Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC63946
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ44872
- http://www-01.ibm.com/support/docview.wss?uid=swg21293566Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg21412902Vendor Advisory
- http://www.securityfocus.com/bid/37332
- http://www.vupen.com/english/advisories/2009/3520Vendor Advisory
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT
- http://secunia.com/advisories/37759Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC63946
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ44872
- http://www-01.ibm.com/support/docview.wss?uid=swg21293566Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg21412902Vendor Advisory
- http://www.securityfocus.com/bid/37332
- http://www.vupen.com/english/advisories/2009/3520Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.