First published: Wed Dec 16 2009(Updated: )
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.5-fp2a | |
IBM DB2 Universal Database | =9.5-fp3b | |
IBM DB2 Universal Database | =9.5-fp2 | |
IBM DB2 Universal Database | =9.5-fp3 | |
IBM DB2 Universal Database | =9.5-fp3a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4333 is rated as medium severity due to the potential for unauthorized access to sensitive information.
To remediate CVE-2009-4333, it is recommended to upgrade to a patched version of IBM DB2 9.5, specifically after FP5.
CVE-2009-4333 affects IBM DB2 version 9.5 and its fix packs before FP5.
CVE-2009-4333 is a vulnerability related to information disclosure that can expose passwords.
There are no known effective workarounds for CVE-2009-4333 other than applying the security updates provided by IBM.