CVE-2009-4333

critical

Description

The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.

References

http://www.vupen.com/english/advisories/2009/3520

http://www.securityfocus.com/bid/37332

http://www-01.ibm.com/support/docview.wss?uid=swg21412902

http://www-01.ibm.com/support/docview.wss?uid=swg21293566

http://www-01.ibm.com/support/docview.wss?uid=swg1IZ38819

http://secunia.com/advisories/37759

Details

Source: Mitre, NVD

Published: 2009-12-16

Updated: 2010-06-29

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical