CVE Vulnerabilities

CVE-2009-3473

Published: Sep 29, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.

Affected Software

NameVendorStart VersionEnd Version
Db2Ibm9.1-fp1 (including)9.1-fp1 (including)
Db2Ibm9.1-fp2 (including)9.1-fp2 (including)
Db2Ibm9.1-fp3 (including)9.1-fp3 (including)
Db2Ibm9.1-fp4 (including)9.1-fp4 (including)
Db2Ibm9.1-fp5 (including)9.1-fp5 (including)
Db2Ibm9.1-fp6 (including)9.1-fp6 (including)
Db2Ibm9.1-fp7 (including)9.1-fp7 (including)

References