VYPR
Unrated severityNVD Advisory· Published Apr 3, 2009· Updated Apr 23, 2026

CVE-2009-1239

CVE-2009-1239

Description

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.

Affected products

17
  • IBM/Db217 versions
    cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:*:connect_server:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:*:enterprise_server:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:*:express_server:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp1:unix:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp1:windows:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp2:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp3:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp3a:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp4:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp4a:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp5:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp6:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:*:personal:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:*:workgroup_server:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:*:fp6a:*:*:*:*:*:*range: <=9.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.