CVE-2015-1922
Summary
| CVE | CVE-2015-1922 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-20 01:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: IBM® DB2® LUW contains a bypass security vulnerability in its Data Movement feature (CVE-2015-1922) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Multiple IBM DB2 Products CVE-2015-1922 Security Bypass Vulnerablity | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www-01.ibm.com/support/docview.wss | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM IT08523: SECURITY: DB2 USER CAN DELETE TABLE DATA WITHOUT APPROPRIATE PRIVILEGES (CVE-2015-1922) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM IT08525: SECURITY: DB2 USER CAN DELETE TABLE DATA WITHOUT APPROPRIATE PRIVILEGES (CVE-2015-1922) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IT08526: SECURITY: DB2 USER CAN DELETE TABLE DATA WITHOUT APPROPRIATE PRIVILEGES (CVE-2015-1922) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM DB2 Data Movement Access Control Flaw Lets Remote Authenticated Users Modify Data - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.