Release date:
Updated on:
Affected Systems:
IBM DB2
Unaffected system:
IBM DB2 9.x
IBM DB2 10.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2013-4033
IBM DB2 is a large commercial relational database system. DB2 Connect connects PCs and mobile devices to the organization's mainframe.
IBM DB2 and DB2 Connect 9.7-FP8, 9.8-FP5, 10.1-FP2, 10.5-FP1 have security vulnerabilities, this allows authenticated users to temporarily obtain the SELECT, INSERT, UPDATE, or DELETE permissions on the table with the EXPLAIN permission. To exploit this vulnerability, you must have a valid credential to connect to the database and have the permission to EXPLAIN, SQLADM, or DBADM.
<* Source: vendor
Link: http://www-01.ibm.com/support/docview.wss? Uid = swg21646809
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ibm.com/support/fixcentral/
Http://www-01.ibm.com/support/docview.wss? Uid = swg27007053