CVE-2010-3474

IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-09-20 22:00

Updated : 2023-12-10 11:03


NVD link : CVE-2010-3474

Mitre link : CVE-2010-3474

CVE.ORG link : CVE-2010-3474


JSON object : View

Products Affected

ibm

  • db2
CWE
CWE-264

Permissions, Privileges, and Access Controls