Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM DB2权限许可和访问控制漏洞
Vulnerability Description
IBM DB2是美国IBM公司的一套关系型数据库管理系统。该系统的执行环境主要有UNIX、Linux、IBM i、z/OS以及Windows服务器版本。 IBM DB2 FP3之前的9.7版本由于函数所有者权限的丢失而不能执行预期的drops或者执行相关的无效函数。远程攻击者可以借助这些函数的调用绕过访问限制。
CVSS Information
N/A
Vulnerability Type
N/A