Oval Definition:oval:org.mitre.oval:def:14688
Revision Date:2013-07-29Version:6
Title:IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
Description:IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2011-1846
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):IBM DB2 UDB
Definition Synopsis
  • IBM DB2 UDB is installed
  • AND Determine if the version of IBM DB2 UDB is less than or equal to 9.7
  • AND Determine if the version of IBM DB2 UDB is greater than or equal to 9.5
  • BACK