CVE-2010-3734

IBM DB2 UDB 9.5 - Unintended Password Length Limit in Install Component

Title source: llm
STIX 2.1

Description

The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14764
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC62856

Scores

EPSS 0.0143
EPSS Percentile 70.2%

Details

CWE
CWE-264
Status published
Products (1)
ibm/db2 9.5 (10 CPE variants)
Published Oct 05, 2010
Tracked Since Feb 18, 2026