First published: Wed Dec 16 2009(Updated: )
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.5 | |
IBM Db2 | =9.5-fp1 | |
IBM Db2 | =9.5-fp2a | |
IBM Db2 | =9.5-fp3b | |
IBM Db2 | =9.5-fp2 | |
IBM Db2 | =9.7 | |
IBM Db2 | =9.5-fp3 | |
IBM Db2 | =9.5-fp3a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4326 is classified as a high-severity vulnerability due to its potential to allow attackers to predict random values.
To resolve CVE-2009-4326, upgrade to IBM DB2 version 9.5 FP5 or 9.7 FP1 or later.
IBM DB2 versions 9.5 before FP5 and 9.7 before FP1, particularly when using the Database Partitioning Feature, are affected by CVE-2009-4326.
CVE-2009-4326 can compromise protection mechanisms that rely on randomization, making systems vulnerable to attacks.
There are no known effective workarounds for CVE-2009-4326, and it is recommended to apply updates as soon as possible.