CVE-2010-3196: Low severity ibm db2 universal database vulnerability
Published Aug 31, 2010
·Updated
IBM DB2 9.7 before FP2, when AUTOREVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.
Affected Software
2 affected components
IBM DB2=9.7-fp1
IBM DB2=9.7
Event History
Aug 31, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3196?
CVE-2010-3196 is categorized as a denial of service vulnerability that can lead to a loss of privileges.
2
How do I fix CVE-2010-3196?
To address CVE-2010-3196, upgrade your IBM DB2 to at least version 9.7 FP2.
3
Who is affected by CVE-2010-3196?
CVE-2010-3196 affects users of IBM DB2 versions 9.7 before FP2 when AUTO_REVAL is set to IMMEDIATE.
4
What type of attack is facilitated by CVE-2010-3196?
CVE-2010-3196 can be exploited by remote authenticated users to create a dependent view, causing a denial of service.
5
Is there a workaround for CVE-2010-3196?
A potential workaround for CVE-2010-3196 is to avoid defining dependent views when AUTO_REVAL is set to IMMEDIATE.