CVE-2009-1905: Low severity IBM DB2 vulnerability
The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1905?
CVE-2009-1905 is classified as a critical vulnerability due to its potential to allow unauthorized access to databases.
How do I fix CVE-2009-1905?
To mitigate CVE-2009-1905, update IBM DB2 to the latest fix pack where this vulnerability has been patched.
Which versions of IBM DB2 are affected by CVE-2009-1905?
CVE-2009-1905 affects IBM DB2 versions 8.0 before FP17, 9.1 before FP7, and 9.5 before FP4.
Can CVE-2009-1905 be exploited remotely?
Yes, CVE-2009-1905 can be exploited remotely by attackers under certain configurations.
What security feature is compromised in CVE-2009-1905?
CVE-2009-1905 compromises password authentication when LDAP security and anonymous bind are enabled.