CVE-2011-0757

IBM DB2 < 9.1 FP10, < 9.5 FP6a, < 9.7 FP2 - Authenticated Non-DDL Statement Execution via Improper DBADM Revocation

Title source: llm
STIX 2.1

Description

IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.

References (12)

Core 12
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1IC66814
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43148
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1IC66815
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21426108
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70773
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14295
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65008
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46064
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1IC66811

Scores

EPSS 0.0235
EPSS Percentile 81.9%

Details

CWE
CWE-264
Status published
Products (6)
ibm/db2 9.1 (14 CPE variants)
ibm/db2 9.5 (10 CPE variants)
ibm/db2 9.7
ibm/db2 < 9.1
ibm/db2 < 9.5
ibm/db2 < 9.7
Published Feb 02, 2011
Tracked Since Feb 18, 2026