CVE-2010-3739: Medium severity ibm db2 universal database vulnerability
The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3739?
CVE-2010-3739 is considered to have a moderate severity level.
How can I mitigate the risks associated with CVE-2010-3739?
Mitigation for CVE-2010-3739 involves applying the latest fixpack or updating to a version of IBM DB2 UDB that addresses this vulnerability.
What components of IBM DB2 UDB are affected by CVE-2010-3739?
CVE-2010-3739 affects the audit facility in the Security component of IBM DB2 UDB versions prior to FP6a.
What types of events are associated with CVE-2010-3739?
CVE-2010-3739 is related to the improper capturing of connection and authentication events.
Can remote attackers exploit CVE-2010-3739?
Yes, CVE-2010-3739 could potentially be exploited by remote attackers due to the flawed audit settings.