CVE-2010-3475: Medium severity IBM DB2 vulnerability
IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3475?
CVE-2010-3475 is classified as having a medium severity due to its potential to allow unauthorized data manipulation.
How do I fix CVE-2010-3475?
To fix CVE-2010-3475, update IBM DB2 to at least version 9.7 FP3 or later.
What are the potential impacts of CVE-2010-3475?
The vulnerability can allow remote authenticated users to execute unauthorized SQL statements, which can lead to data integrity issues.
Which versions of IBM DB2 are affected by CVE-2010-3475?
CVE-2010-3475 affects IBM DB2 versions 9.7.0.1, 9.7.0.2, and 9.7 without the latest fixes.
Who can exploit CVE-2010-3475?
CVE-2010-3475 can be exploited by remote authenticated users with access to the dynamic SQL cache.