CVE-2009-3473
https://notcve.org/view.php?id=CVE-2009-3473
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors. IBM DB2 v9.1 anterior a FP8 no requiere el privilegio SETSESSIONUSER para la sentencia SET SESSION AUTHORIZATION, lo que tiene un impacto y vectores de ataque no especificados. • http://osvdb.org/58479 http://secunia.com/advisories/36890 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55883 http://www-01.ibm.com/support/docview.wss?uid=swg21403619 http://www.securityfocus.com/bid/36540 •
CVE-2009-2858
https://notcve.org/view.php?id=CVE-2009-2858
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure. Fuga de memoria en el componente de seguridad en IBM DB2 v8.1 anteriores a FP18 en plataformas Unix permite a atacantes producir una denegación de servicio a través de vectores sin especificar, relacionado con la memoria privada dentro de la estructura de memoria de DB2. • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT http://secunia.com/advisories/36313 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ35635 http://www-01.ibm.com/support/docview.wss?uid=swg24024075 • CWE-399: Resource Management Errors •
CVE-2009-2859
https://notcve.org/view.php?id=CVE-2009-2859
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command. IBM DB2 v8.1 anterior a FP18 permite a atacantes obtener acceso sin especificar a través del comando "das". • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT http://secunia.com/advisories/36313 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ34149 http://www-01.ibm.com/support/docview.wss?uid=swg24024075 http://www.vupen.com/english/advisories/2009/2293 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2009-2860
https://notcve.org/view.php?id=CVE-2009-2860
Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets." Vulnerabilidad inespecífica en db2jds en IBM DB2 v8.1 anteriores a FP18 permite a atacantes remotos producir una denegación de servicio (caída de servicio) a través de "paquetes maliciosos". • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT http://secunia.com/advisories/36313 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ52433 http://www-01.ibm.com/support/docview.wss?uid=swg24024075 http://www.vupen.com/english/advisories/2009/2293 •
CVE-2008-6820
https://notcve.org/view.php?id=CVE-2008-6820
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856. El proceso db2fmp en IBM DB2 v8 anterior a FP17, v9.1 anterior a FP5 y v9.5 anterior a FP2 sobre Windows, se ejecuta con "privilegios OS" lo que tiene unos vectores de ataque e impacto desconocidos. Vulnerabilidad distinta de CVE-2008-3856. • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT http://osvdb.org/48149 http://www-01.ibm.com/support/docview.wss?uid=swg1JR30026 http://www-01.ibm.com/support/docview.wss?uid=swg1JR30227 http://www-01.ibm.com/support/docview.wss?uid=swg1JR30228 http://www-01.ibm.com/support/docview.wss?uid=swg21318189 http://www.securityfocus.com/bid/31058 • CWE-16: Configuration •