CVE-2010-3197: Medium severity ibm db2 universal database vulnerability
Published Aug 31, 2010
·Updated
IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
2 affected components
IBM DB2=9.7-fp1
IBM DB2=9.7
Event History
Aug 31, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3197?
CVE-2010-3197 is classified as a moderate severity vulnerability due to unauthorized access to sensitive information.
2
How do I fix CVE-2010-3197?
To mitigate CVE-2010-3197, upgrade IBM DB2 to version 9.7 FP2 or later.
3
What type of access does CVE-2010-3197 exploit?
CVE-2010-3197 exploits insufficient access control on the monitor administrative views in the SYSIBMADM schema.
4
Who is affected by CVE-2010-3197?
CVE-2010-3197 affects installations of IBM DB2 version 9.7 before FP2.
5
What are potential consequences of CVE-2010-3197?
The exploitation of CVE-2010-3197 may lead to remote attackers obtaining sensitive information from the database.