CVE-2010-3475
 
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.
IBM DB2 v9.7 anteriores a FP3 no aplican correctamente los requisitos de privilegio para la ejecución de las entradas en la caché dinámica SQL, lo que permite a usuarios remotos autenticados eludir las restricciones de acceso destinados al aprovechar la caché para ejecutar una instrucción UPDATE contenida en una sentencia compilada de SQL.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-09-20 CVE Reserved
- 2010-09-20 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://osvdb.org/68122 | Vdb Entry | |
http://www.ibm.com/support/docview.wss?uid=swg21446455 | X_refsource_confirm | |
http://www.securityfocus.com/bid/43291 | Vdb Entry | |
http://www.securitytracker.com/id?1024458 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/61873 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14609 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/41444 | 2017-09-19 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IC70406 | 2017-09-19 | |
http://www.vupen.com/english/advisories/2010/2425 | 2017-09-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7 Search vendor "Ibm" for product "Db2" and version "9.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7.0.1 Search vendor "Ibm" for product "Db2" and version "9.7.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | 9.7.0.2 Search vendor "Ibm" for product "Db2" and version "9.7.0.2" | - |
Affected
|