CVE-2011-1846

I

BM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2:*:fp6a:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp1:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp2:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp2a:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp3:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp3a:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp3b:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp4:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp4a:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp5:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp6:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ibm:db2:*:fp3:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7:fp1:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7:fp2:*:*:*:*:*:*

History

21 Nov 2024, 01:27

Type Values Removed Values Added
References () http://secunia.com/advisories/44229 - Vendor Advisory () http://secunia.com/advisories/44229 - Vendor Advisory
References () http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263 - () http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263 -
References () http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375 - () http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263 - () http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375 - () http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375 -
References () http://www.securityfocus.com/bid/47525 - () http://www.securityfocus.com/bid/47525 -
References () http://www.vupen.com/english/advisories/2011/1083 - Vendor Advisory () http://www.vupen.com/english/advisories/2011/1083 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/66980 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/66980 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14688 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14688 -

Information

Published : 2011-05-03 20:55

Updated : 2025-04-11 00:51


NVD link : CVE-2011-1846

Mitre link : CVE-2011-1846

CVE.ORG link : CVE-2011-1846


JSON object : View

Products Affected
CWE
CWE-264

Permissions, Privileges, and Access Controls