CVE-2009-1239

high

Description

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/49864

http://www.vupen.com/english/advisories/2009/0912

http://www-01.ibm.com/support/docview.wss?uid=swg21381257

http://www-01.ibm.com/support/docview.wss?uid=swg1JR31886

Details

Source: Mitre, NVD

Published: 2009-04-03

Updated: 2017-08-17

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High