The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IC98849 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IC99478 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IC99480 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IC99481 - | |
References | () http://www.ibm.com/support/docview.wss?uid=swg1IC99480 - Vendor Advisory | |
References | () http://www.ibm.com/support/docview.wss?uid=swg21610582#4 - | |
References | () http://www.ibm.com/support/docview.wss?uid=swg21673947 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/89860 - |
Information
Published : 2014-05-30 23:55
Updated : 2024-11-21 01:59
NVD link : CVE-2013-6744
Mitre link : CVE-2013-6744
CVE.ORG link : CVE-2013-6744
JSON object : View
Products Affected
microsoft
- windows
ibm
- db2
CWE
CWE-264
Permissions, Privileges, and Access Controls