First published: Wed Oct 22 2008(Updated: )
The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 | =8.0-fp11 | |
Ibm Db2 | =8.0-fp3 | |
Ibm Db2 | =8.0-fp10 | |
Ibm Db2 | =9.1-fp4 | |
Ibm Db2 | =9.5 | |
Ibm Db2 | =9.1-fp1 | |
Ibm Db2 | =8.0-fp9 | |
Ibm Db2 | =8.0-fp7b | |
Ibm Db2 | =8.0-fp6a | |
Ibm Db2 | =8.0-fp9a | |
Ibm Db2 | =9.1 | |
Ibm Db2 | =8.0-fp4 | |
Ibm Db2 | =9.1-fp3 | |
Ibm Db2 | =8.0-fp7a | |
Ibm Db2 | =8.0-fp6 | |
Ibm Db2 | =9.1-fp3a | |
Ibm Db2 | =8.0-fp8 | |
Ibm Db2 | =8.0-fp14 | |
Ibm Db2 | <=9.1 | |
Ibm Db2 | =8.0-fp2 | |
Ibm Db2 | <=8.0 | |
Ibm Db2 | =8.0-fp1 | |
Ibm Db2 | =8.0-fp4a | |
Ibm Db2 | =8.0-fp5 | |
Ibm Db2 | =9.1-fp2 | |
Ibm Db2 | <=9.5 | |
Ibm Db2 | =8.0-fp6c | |
Ibm Db2 | =9.1-fp4a | |
Ibm Db2 | =8.0-fp13 | |
Ibm Db2 | =8.0-fp8a | |
Ibm Db2 | =8.0-fp12 | |
Ibm Db2 | =8.0-fp6b | |
Ibm Db2 | =8.0-fp15 | |
Ibm Db2 | =8.0-fp7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-4692 is considered unknown as it has undetermined impacts and attack vectors.
To address CVE-2008-4692, users should upgrade to a version of IBM DB2 that is beyond the affected releases as outlined by IBM's security advisories.
CVE-2008-4692 affects IBM DB2 versions 8 before FP17, 9.1 before FP6, and 9.5 before FP2.
The impact of CVE-2008-4692 stems from maintaining views and triggers without proper management, leading to potential security risks.
Currently, there are no known workarounds for CVE-2008-4692, so upgrading to a patched version is recommended.