CVE-2009-3473: Critical severity ibm db2 universal database vulnerability
Published Sep 29, 2009
·Updated
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
Affected Software
7 affected components
IBM DB2=9.1-fp4
IBM DB2=9.1-fp1
IBM DB2=9.1-fp5
IBM DB2=9.1-fp3
IBM DB2=9.1-fp6
IBM DB2=9.1-fp2
IBM DB2=9.1-fp7
Event History
Sep 29, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3473?
CVE-2009-3473 has an unspecified severity rating but poses remote attack vectors.
2
How do I fix CVE-2009-3473?
To mitigate CVE-2009-3473, upgrade to IBM DB2 9.1 Fix Pack 8 or later.
3
What versions of IBM DB2 are affected by CVE-2009-3473?
IBM DB2 versions 9.1 before Fix Pack 8, including FP1 to FP7, are affected by CVE-2009-3473.
4
What is the impact of CVE-2009-3473?
The impact of CVE-2009-3473 lies in the lack of required privileges for session authorization, potentially allowing unauthorized actions.
5
Can CVE-2009-3473 be exploited remotely?
Yes, CVE-2009-3473 can be exploited through unspecified remote attack vectors.