CVE-2011-1846
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a…
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/db2
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/44229Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263
- http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375
- http://www.securityfocus.com/bid/47525
- http://www.vupen.com/english/advisories/2011/1083Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66980
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14688
- http://secunia.com/advisories/44229Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263
- http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375
- http://www.securityfocus.com/bid/47525
- http://www.vupen.com/english/advisories/2011/1083Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66980
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14688
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.