First published: Tue Aug 31 2010(Updated: )
IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 | =9.7-fp1 | |
Ibm Db2 | =9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3196 is categorized as a denial of service vulnerability that can lead to a loss of privileges.
To address CVE-2010-3196, upgrade your IBM DB2 to at least version 9.7 FP2.
CVE-2010-3196 affects users of IBM DB2 versions 9.7 before FP2 when AUTO_REVAL is set to IMMEDIATE.
CVE-2010-3196 can be exploited by remote authenticated users to create a dependent view, causing a denial of service.
A potential workaround for CVE-2010-3196 is to avoid defining dependent views when AUTO_REVAL is set to IMMEDIATE.