First published: Wed Aug 28 2013(Updated: )
IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 | =9.7 | |
Ibm Db2 | =9.8 | |
Ibm Db2 | =10.1 | |
Ibm Db2 | =10.5 | |
IBM DB2 Connect | =9.5 | |
IBM DB2 Connect | =9.7 | |
IBM DB2 Connect | =9.8 | |
IBM DB2 Connect | =10.1 | |
IBM DB2 Connect | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4033 has a medium severity rating, indicating a potential risk to systems using the affected IBM DB2 versions.
To fix CVE-2013-4033, apply the recommended patches or update to non-vulnerable versions of IBM DB2 and DB2 Connect.
CVE-2013-4033 affects remote authenticated users of IBM DB2 and DB2 Connect on specific versions listed in the vulnerability details.
CVE-2013-4033 can facilitate unauthorized execution of DML statements by users with EXPLAIN authority.
While the primary solution is to patch, a temporary workaround may include restricting EXPLAIN authority for users until a patch is applied.