CVE-2011-1846

high

Description

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14688

https://exchange.xforce.ibmcloud.com/vulnerabilities/66980

http://www.vupen.com/english/advisories/2011/1083

http://www.securityfocus.com/bid/47525

http://www-01.ibm.com/support/docview.wss?uid=swg1IC71375

http://www-01.ibm.com/support/docview.wss?uid=swg1IC71263

http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71375

http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC71263

http://secunia.com/advisories/44229

Details

Source: Mitre, NVD

Published: 2011-05-03

Updated: 2017-09-19

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Severity: High