First published: Tue Aug 31 2010(Updated: )
IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 | =9.7-fp1 | |
Ibm Db2 | =9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3197 is classified as a moderate severity vulnerability due to unauthorized access to sensitive information.
To mitigate CVE-2010-3197, upgrade IBM DB2 to version 9.7 FP2 or later.
CVE-2010-3197 exploits insufficient access control on the monitor administrative views in the SYSIBMADM schema.
CVE-2010-3197 affects installations of IBM DB2 version 9.7 before FP2.
The exploitation of CVE-2010-3197 may lead to remote attackers obtaining sensitive information from the database.