CVE-2010-3197

IBM DB2 9.7 - Unauthenticated Sensitive Information Exposure via SYSIBMADM Schema Monitor Views

Title source: llm
STIX 2.1

Description

IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14430
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC67819
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21432298

Scores

EPSS 0.0188
EPSS Percentile 77.2%

Details

CWE
CWE-264
Status published
Products (1)
ibm/db2 9.7 (2 CPE variants)
Published Aug 31, 2010
Tracked Since Feb 18, 2026