Page 34 of 228 results (0.008 seconds)

CVSS: 5.0EPSS: 0%CPEs: 3EXPL: 0

IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471. IBM DB2 v9.7 anteriores a FP3 no realiza las descargas esperadas o invalidaciones de las funciones dependientes de una pérdida de privilegios por los propietarios de las funciones, que permite a los usuarios remotos autenticados eludir las restricciones de acceso a través de llamadas a estas funciones, una vulnerabilidad diferente de CVE-2009-3471 • http://osvdb.org/68121 http://secunia.com/advisories/41444 http://www-01.ibm.com/support/docview.wss?uid=swg1IC68015 http://www.ibm.com/support/docview.wss?uid=swg21446455 http://www.securityfocus.com/bid/43291 http://www.securitytracker.com/id?1024457 http://www.vupen.com/english/advisories/2010/2425 https://exchange.xforce.ibmcloud.com/vulnerabilities/61872 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14669 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.0EPSS: 0%CPEs: 3EXPL: 0

IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement. IBM DB2 v9.7 anteriores a FP3 no aplican correctamente los requisitos de privilegio para la ejecución de las entradas en la caché dinámica SQL, lo que permite a usuarios remotos autenticados eludir las restricciones de acceso destinados al aprovechar la caché para ejecutar una instrucción UPDATE contenida en una sentencia compilada de SQL. • http://osvdb.org/68122 http://secunia.com/advisories/41444 http://www-01.ibm.com/support/docview.wss?uid=swg1IC70406 http://www.ibm.com/support/docview.wss?uid=swg21446455 http://www.securityfocus.com/bid/43291 http://www.securitytracker.com/id?1024458 http://www.vupen.com/english/advisories/2010/2425 https://exchange.xforce.ibmcloud.com/vulnerabilities/61873 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14609 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.5EPSS: 0%CPEs: 26EXPL: 0

The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner. El programa DB2DART en IBM DB2 v9.1 anterior a FP9, v9.5 anterior a FP6, y v9.7 anterior a FP2 permite a atacantes evitar las restricciones de los ficheros de acceso previstas a través de vectores sin especificar relacionados con con la sobreescritura de ficheros propietarios por una instancia propietaria. • ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT http://secunia.com/advisories/41218 http://www-01.ibm.com/support/docview.wss?uid=swg1IC65749 http://www-01.ibm.com/support/docview.wss?uid=swg1IC65756 http://www-01.ibm.com/support/docview.wss?uid=swg1IC65762 http://www-01.ibm.com/support/docview.wss?uid=swg21426108 http://www-01.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 10.0EPSS: 0%CPEs: 26EXPL: 0

Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors. Vulnerabilidad sin especificar en el programa DB2STST en IBM DB2 v9.1 anterior a FP9, v9.5 anterior a FP6, y v9.7 anterior a FP2 tienen un impacto y vactores de ataque desconocidos. • ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT http://secunia.com/advisories/41218 http://www-01.ibm.com/support/docview.wss?uid=swg1IC65408 http://www-01.ibm.com/support/docview.wss?uid=swg1IC65703 http://www-01.ibm.com/support/docview.wss?uid=swg1IC65742 http://www-01.ibm.com/support/docview.wss?uid=swg21426108 http://www-01.ibm.com/support/docview.wss? •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors. IBM DB2 v9.7 anterior a FP2 no realiza correctamente el control de acceso en el monitor de vistas administrativas en el esquema SYSIBMADM, lo que permite a atacantes remotos obtener información sensible a través de vectores sin especificar. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC67819 http://www-01.ibm.com/support/docview.wss?uid=swg21432298 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14430 • CWE-264: Permissions, Privileges, and Access Controls •