CVE-2012-0709
Summary
| CVE | CVE-2012-0709 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-03-20 20:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.5 | fp1 | All | All |
| Application | Ibm | Db2 | 9.5 | fp2 | All | All |
| Application | Ibm | Db2 | 9.5 | fp2a | All | All |
| Application | Ibm | Db2 | 9.5 | fp3 | All | All |
| Application | Ibm | Db2 | 9.5 | fp3a | All | All |
| Application | Ibm | Db2 | 9.5 | fp3b | All | All |
| Application | Ibm | Db2 | 9.5 | fp4 | All | All |
| Application | Ibm | Db2 | 9.5 | fp4a | All | All |
| Application | Ibm | Db2 | 9.5 | fp5 | All | All |
| Application | Ibm | Db2 | 9.5 | fp6 | All | All |
| Application | Ibm | Db2 | 9.5 | fp6a | All | All |
| Application | Ibm | Db2 | 9.5 | fp7 | All | All |
| Application | Ibm | Db2 | 9.5 | fp8 | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7 | fp1 | All | All |
| Application | Ibm | Db2 | 9.7 | fp2 | All | All |
| Application | Ibm | Db2 | 9.7 | fp3 | All | All |
| Application | Ibm | Db2 | 9.7 | fp3a | All | All |
| Application | Ibm | Db2 | 9.7 | fp4 | All | All |
| Application | Ibm | Db2 | 9.7 | fp5 | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8 | fp3 | All | All |
| Application | Ibm | Db2 | 9.8 | fp4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM IC81387: SECURITY: UNAUTHORIZED ACCESS TO TABLES | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM IC81390: SECURITY: UNAUTHORIZED ACCESS TO TABLES | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Security Bulletin: Unauthorized Access to Table Vulnerability in DB2 (CVE-2012-0709) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM IC81836: SECURITY: UNAUTHORIZED ACCESS TO TABLES | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.