CVE-2011-0757 Information
Description
IBM DB2 9.1 before FP10 9.5 before FP6a and 9.7 before FP2 on Linux UNIX and Windows does not properly revoke the DBADM authority which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.
Reference
http://osvdb.org/70773 http://secunia.com/advisories/43148 http://www.ibm.com/support/docview.wss?uid=swg1IC66811 http://www.ibm.com/support/docview.wss?uid=swg1IC66814 http://www.ibm.com/support/docview.wss?uid=swg1IC66815 http://www.ibm.com/support/docview.wss?uid=swg21426108 http://www.securityfocus.com/bid/46064 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66811 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66814 http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC66815 https://exchange.xforce.ibmcloud.com/vulnerabilities/65008 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A14295
Share on: