CVE-2009-4438: Medium severity ibm db2 universal database vulnerability
The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4438?
CVE-2009-4438 is considered a medium severity vulnerability due to privilege escalation risks.
How do I fix CVE-2009-4438?
To fix CVE-2009-4438, update IBM DB2 to a version that is not affected, specifically to version 9.1 FP8 or later, 9.5 FP5 or later, or 9.7 FP1 or later.
What is affected by CVE-2009-4438?
CVE-2009-4438 affects IBM DB2 versions 9.1 prior to FP8, 9.5 prior to FP5, and 9.7 prior to FP1.
Who can exploit CVE-2009-4438?
CVE-2009-4438 can be exploited by remote authenticated users who have access to the vulnerable DB2 instance.
What types of objects are involved in CVE-2009-4438?
CVE-2009-4438 involves access to sequence and global-variable objects within the IBM DB2 environment.