VYPR
Unrated severityNVD Advisory· Published Sep 20, 2010· Updated Jun 16, 2026

CVE-2010-3475

CVE-2010-3475

Description

IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.

Affected products

4
  • IBM/Db24 versions
    cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:*:*:*:*
    • (no CPE)range: <=9.7

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.