VYPR
Unrated severityNVD Advisory· Published Aug 28, 2013· Updated Apr 29, 2026

CVE-2013-4033

CVE-2013-4033

Description

IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.

Affected products

9
  • IBM/Db24 versions
    cpe:2.3:a:ibm:db2:10.1:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ibm:db2:10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:10.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.8:*:*:*:*:*:*:*
  • IBM/Db2 Connect5 versions
    cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2_connect:10.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2_connect:9.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2_connect:9.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2_connect:9.8:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.