Back to search
CVE-2009-4333
Published: Dec 16, 2009
Modified: Sep 17, 2024
PUBLISHED
Description
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www-01.ibm.com/support/docview.wss?uid=swg21293566
x_refsource_CONFIRM
ADV-2009-3520
vdb-entry
x_refsource_VUPEN
37332
vdb-entry
x_refsource_BID
IZ38819
vendor-advisory
x_refsource_AIXAPAR
http://www-01.ibm.com/support/docview.wss?uid=swg21412902
x_refsource_CONFIRM
37759
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now