IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Db2 | Ibm | 9.1-fp1 (including) | 9.1-fp1 (including) |
Db2 | Ibm | 9.1-fp2 (including) | 9.1-fp2 (including) |
Db2 | Ibm | 9.1-fp3 (including) | 9.1-fp3 (including) |
Db2 | Ibm | 9.1-fp4 (including) | 9.1-fp4 (including) |
Db2 | Ibm | 9.1-fp5 (including) | 9.1-fp5 (including) |
Db2 | Ibm | 9.1-fp6 (including) | 9.1-fp6 (including) |
Db2 | Ibm | 9.1-fp7 (including) | 9.1-fp7 (including) |