CVE-2009-4150

IBM DB2 <9.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.

References (10)

Core 10
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ40343
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC64759
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36890
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21403619
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023242
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ40340
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3340
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37454
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ40352
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21386689

Scores

EPSS 0.0044
EPSS Percentile 35.7%

Details

CWE
CWE-264
Status published
Products (4)
ibm/db2 9.1 fp1 (9 CPE variants)
ibm/db2 9.5 fp1 (3 CPE variants)
ibm/db2 9.7
ibm/db2_universal_database 8 (37 CPE variants)
Published Dec 02, 2009
Tracked Since Feb 18, 2026