CVE-2010-3474: Medium severity IBM DB2 vulnerability
IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3474?
CVE-2010-3474 is classified as having a medium severity due to its potential for privilege escalation.
How do I fix CVE-2010-3474?
To fix CVE-2010-3474, upgrade to IBM DB2 version 9.7 FP3 or later, which addresses this vulnerability.
Who is affected by CVE-2010-3474?
CVE-2010-3474 affects IBM DB2 versions 9.7.0.1, 9.7.0.2, and 9.7, allowing remote authenticated users access to restricted functions.
What type of vulnerability is CVE-2010-3474?
CVE-2010-3474 is a privilege escalation vulnerability that allows unauthorized users to bypass access controls.
Can CVE-2010-3474 be exploited remotely?
Yes, CVE-2010-3474 can be exploited remotely by authenticated users who leverage the vulnerability to access restricted functions.