CVE-2009-3471: High severity ibm db2 universal database vulnerability
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3471?
The severity of CVE-2009-3471 is considered moderate due to its potential for exploitation in certain scenarios.
How do I fix CVE-2009-3471?
To fix CVE-2009-3471, upgrade to an unaffected version of IBM DB2, specifically versions after FP18 for 8, FP8 for 9.1, FP4 for 9.5, and FP2 for 9.7.
Which versions of IBM DB2 are affected by CVE-2009-3471?
CVE-2009-3471 affects IBM DB2 versions 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2.
What kind of impact can CVE-2009-3471 have?
CVE-2009-3471 can lead to unspecified impacts, especially regarding unauthorized access to table functions upon a loss of privileges.
Are remote attack vectors possible with CVE-2009-3471?
Yes, CVE-2009-3471 has potential remote attack vectors that could exploit the vulnerability if not mitigated.