CVE-2009-3473
29.09.2009, 21:30
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1:fp1 |
| ibm | db2 | 9.1:fp2 |
| ibm | db2 | 9.1:fp3 |
| ibm | db2 | 9.1:fp4 |
| ibm | db2 | 9.1:fp5 |
| ibm | db2 | 9.1:fp6 |
| ibm | db2 | 9.1:fp7 |
𝑥
= Vulnerable software versions
References