Vulnerability Name: | CVE-2009-4333 (CCN-55012) | ||||||||
Assigned: | 2009-12-15 | ||||||||
Published: | 2009-12-15 | ||||||||
Updated: | 2010-06-29 | ||||||||
Summary: | The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CONFIRM Type: UNKNOWN ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT Source: MITRE Type: CNA CVE-2009-4333 Source: CCN Type: SA37759 IBM DB2 Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 37759 Source: AIXAPAR Type: Vendor Advisory IZ38819 Source: CCN Type: IBM Support & downloads IZ38819: SECURITY: VISIBILITY OF PASSWORDS IN SET ENCRYPTION PASSWORD STATEMENT Source: CONFIRM Type: Patch http://www-01.ibm.com/support/docview.wss?uid=swg21293566 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21412902 Source: CCN Type: OSVDB ID: 67684 IBM DB2 Universal Database Relational Data Services Component SET ENCRYPTION PASSWORD Statement Password Disclosure Source: BID Type: UNKNOWN 37332 Source: CCN Type: BID-37332 IBM DB2 prior to 9.5 Fix Pack 5 Multiple Unspecified Security Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2009-3520 Source: XF Type: UNKNOWN ibm-db2-relationaldata-info-disclosure(55012) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |