CVE-2010-3734
IBM DB2 UDB 9.5 - Unintended Password Length Limit in Install Component
Title source: llmDescription
The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14764
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC62856
Various Sources x_refsource_confirm
ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
Scores
EPSS
0.0143
EPSS Percentile
70.2%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/db2
9.5 (10 CPE variants)
Published
Oct 05, 2010
Tracked Since
Feb 18, 2026