CVE-2012-0709: Input Validation
IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0709?
CVE-2012-0709 is considered a high severity vulnerability due to its potential for data visibility bypass by authenticated users.
How do I fix CVE-2012-0709?
To fix CVE-2012-0709, upgrade the IBM DB2 software to the latest version or apply all necessary fixes and patches provided by IBM.
Who is affected by CVE-2012-0709?
CVE-2012-0709 affects IBM DB2 versions 9.5 prior to FP9, 9.7 through FP5, and 9.8 through FP4.
Can CVE-2012-0709 be exploited remotely?
Yes, CVE-2012-0709 can be exploited by remote authenticated users via manipulated SQL statements.
What type of vulnerability is CVE-2012-0709?
CVE-2012-0709 is a type of SQL Injection vulnerability allowing unauthorized access to sensitive data.