CVE-2009-2859: Medium severity IBM DB2 vulnerability
Published Aug 19, 2009
·Updated
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.
Affected Software
24 affected components
IBM DB2=8.1-fp1
IBM DB2=8.1-fp10
IBM DB2=8.1-fp6c
IBM DB2=8.1-fp2
IBM DB2<=8.1
IBM DB2=8.1-fp5
IBM DB2=8.1-fp8
IBM DB2=8.1-fp8a
IBM DB2=8.1-fp14
IBM DB2=8.1-fp11
IBM DB2=8.1-fp7
IBM DB2=8.1-fp6b
IBM DB2=8.1-fp17a
IBM DB2=8.1-fp15
IBM DB2=8.1-fp9a
IBM DB2=8.1-fp12
IBM DB2=8.1-fp4
IBM DB2=8.1-fp4a
IBM DB2=8.1-fp6
IBM DB2=8.1-fp13
IBM DB2=8.1-fp3
IBM DB2=8.1-fp7a
IBM DB2=8.1-fp9
IBM DB2=8.1-fp6a
Remediation
Patch Available
Patch Available
Event History
Aug 19, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2859?
The severity of CVE-2009-2859 is classified as medium risk due to the potential for unauthorized access.
2
How do I fix CVE-2009-2859?
To fix CVE-2009-2859, users should upgrade IBM DB2 to version 8.1 Fix Pack 18 or later.
3
What versions of IBM DB2 are affected by CVE-2009-2859?
CVE-2009-2859 affects IBM DB2 8.1 prior to Fix Pack 18.
4
What type of access can an attacker gain through CVE-2009-2859?
An attacker can gain unspecified access through the use of a das command in CVE-2009-2859.
5
Is there a workaround for CVE-2009-2859 if upgrading is not possible?
Currently, there is no documented workaround for CVE-2009-2859, and upgrading is the recommended approach.