CVE-2007-1089

IBM DB2 UDB <9.1 FP1 - SQL Injection

Title source: llm
STIX 2.1

Description

IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.

References (4)

Core 4
Core References
Patch third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24283
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1JR25941
Third Party Advisory mailing-list x_refsource_vim
http://www.attrition.org/pipermail/vim/2007-August/001765.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0721

Scores

EPSS 0.0030
EPSS Percentile 22.8%

Details

Status published
Products (2)
ibm/db2_universal_database 9.1 ga
ibm/db2_universal_database < 9.1
Published Feb 23, 2007
Tracked Since Feb 18, 2026