IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Db2 | Ibm | 9.7 (including) | 9.7 (including) |
Db2 | Ibm | 9.7.0.1 (including) | 9.7.0.1 (including) |
Db2 | Ibm | 9.7.0.2 (including) | 9.7.0.2 (including) |