CVE-2009-4150
https://notcve.org/view.php?id=CVE-2009-4150
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors. dasauto en IBM DB2 v8 anterior a FP18, v9.1 anterior a FP8, v9.5 anterior a FP4, y v9.7 anterior a FP1, permite la ejecución a través de cuentas de usuario sin privilegios, lo que tiene un impacto y vectores de ataque no especificados. • http://secunia.com/advisories/36890 http://secunia.com/advisories/37454 http://securitytracker.com/id?1023242 http://www-01.ibm.com/support/docview.wss?uid=swg1IC64759 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ40340 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ40343 http://www-01.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2009-3471
https://notcve.org/view.php?id=CVE-2009-3471
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors. IBM DB2 v8 anterior a FP18, v9.1 anterior a FP8, y v9.5 anterior a FP4 no realiza los borrados esperados de ciertas funciones de tabla por una perdida de privilegios por las definiciones de las funciones, lo cual tiene un impacto no especificado y vectores de ataque a distancia. • ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT http://osvdb.org/58477 http://secunia.com/advisories/36890 http://www-01.ibm.com/support/docview.wss?uid=swg1IC63548 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46658 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46773 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ46774 http://www-01.ibm.com/support/docview.wss? •
CVE-2009-3472
https://notcve.org/view.php?id=CVE-2009-3472
IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors. IBM DB2 8 anterior a FP18, v9.1 anterior a FP8, y v9.5 anterior a FP4 permite a usuarios remotos autenticados eludir las restricciones de acceso, y actualizar, insertar o eliminar filas de la tabla, a través de vectores no especificados. • http://osvdb.org/58478 http://secunia.com/advisories/36890 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50074 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50078 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50079 http://www-01.ibm.com/support/docview.wss?uid=swg21386689 http://www-01.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2009-3473
https://notcve.org/view.php?id=CVE-2009-3473
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors. IBM DB2 v9.1 anterior a FP8 no requiere el privilegio SETSESSIONUSER para la sentencia SET SESSION AUTHORIZATION, lo que tiene un impacto y vectores de ataque no especificados. • http://osvdb.org/58479 http://secunia.com/advisories/36890 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55883 http://www-01.ibm.com/support/docview.wss?uid=swg21403619 http://www.securityfocus.com/bid/36540 •
CVE-2009-2858
https://notcve.org/view.php?id=CVE-2009-2858
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure. Fuga de memoria en el componente de seguridad en IBM DB2 v8.1 anteriores a FP18 en plataformas Unix permite a atacantes producir una denegación de servicio a través de vectores sin especificar, relacionado con la memoria privada dentro de la estructura de memoria de DB2. • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT http://secunia.com/advisories/36313 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ35635 http://www-01.ibm.com/support/docview.wss?uid=swg24024075 • CWE-399: Resource Management Errors •