{"api_version":"1","generated_at":"2026-07-23T10:46:14+00:00","cve":"CVE-2010-3475","urls":{"html":"https://cve.report/CVE-2010-3475","api":"https://cve.report/api/cve/CVE-2010-3475.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-3475","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-3475"},"summary":{"title":"CVE-2010-3475","description":"IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-09-20 22:00:04","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/43291","name":"http://www.securityfocus.com/bid/43291","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM DB2 prior to 9.7 Fix Pack 3 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14609","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/2425","name":"http://www.vupen.com/english/advisories/2010/2425","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/61873","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/61873","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/68122","name":"http://osvdb.org/68122","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.ibm.com/support/docview.wss?uid=swg21446455","name":"http://www.ibm.com/support/docview.wss?uid=swg21446455","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://secunia.com/advisories/41444","name":"http://secunia.com/advisories/41444","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM DB2 Two Security Issues - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1024458","name":"http://www.securitytracker.com/id?1024458","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - IBM DB2 May Let Remote Authenticated Users Update Tables Without Privileges in Certain Cases","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC70406","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC70406","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM IC70406: SECURITY: UPDATE AGAINST A TABLE VIA A COMPOUND SQL (COMPILED)  STATEMENT MAY BE EXECUTED BY USER WTHOUT REQUIRED PRIVILEGES - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-3475","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-3475","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"3475","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"db2","cpe6":"9.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3475","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"db2","cpe6":"9.7.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3475","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"db2","cpe6":"9.7.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:11:44.338Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"43291","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/43291"},{"name":"ADV-2010-2425","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/2425"},{"name":"ibm-db2-sql-security-bypass(61873)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/61873"},{"name":"41444","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41444"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21446455"},{"name":"IC70406","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC70406"},{"name":"68122","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/68122"},{"name":"oval:org.mitre.oval:def:14609","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14609"},{"name":"1024458","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024458"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-09-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"43291","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/43291"},{"name":"ADV-2010-2425","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/2425"},{"name":"ibm-db2-sql-security-bypass(61873)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/61873"},{"name":"41444","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41444"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21446455"},{"name":"IC70406","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC70406"},{"name":"68122","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/68122"},{"name":"oval:org.mitre.oval:def:14609","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14609"},{"name":"1024458","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024458"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-3475","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"43291","refsource":"BID","url":"http://www.securityfocus.com/bid/43291"},{"name":"ADV-2010-2425","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/2425"},{"name":"ibm-db2-sql-security-bypass(61873)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/61873"},{"name":"41444","refsource":"SECUNIA","url":"http://secunia.com/advisories/41444"},{"name":"http://www.ibm.com/support/docview.wss?uid=swg21446455","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg21446455"},{"name":"IC70406","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC70406"},{"name":"68122","refsource":"OSVDB","url":"http://osvdb.org/68122"},{"name":"oval:org.mitre.oval:def:14609","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14609"},{"name":"1024458","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1024458"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-3475","datePublished":"2010-09-20T21:00:00.000Z","dateReserved":"2010-09-20T00:00:00.000Z","dateUpdated":"2024-08-07T03:11:44.338Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-09-20 22:00:04","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*","matchCriteriaId":"CE1C4DE6-EB32-4A31-9FAA-D8DA31D8CF05"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"A8A8E221-7045-4BAD-9B29-ABBC5216559D"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:*:*:*:*","matchCriteriaId":"56C39DC1-AD23-4F26-9727-EC0FBDF84BEE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"3475","Ordinal":"1","Title":"CVE-2010-3475","CVE":"CVE-2010-3475","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"3475","Ordinal":"1","NoteData":"IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.","Type":"Description","Title":"CVE-2010-3475"},{"CveYear":"2010","CveId":"3475","Ordinal":"2","NoteData":"2010-09-20","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"3475","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}