Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-1905

The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.9%
CVSS Severity
CVSS v2 Score 2.6
References
Products affected by CVE-2009-1905
  • Ibm » Db2 » Version: Any
    cpe:2.3:a:ibm:db2:*
  • Ibm » Db2 » Version: 8.0
    cpe:2.3:a:ibm:db2:8.0
  • Ibm » Db2 » Version: 8.2
    cpe:2.3:a:ibm:db2:8.2
  • Ibm » Db2 » Version: 9.0
    cpe:2.3:a:ibm:db2:9.0
  • Ibm » Db2 » Version: 9.1
    cpe:2.3:a:ibm:db2:9.1
  • Ibm » Db2 » Version: 9.5
    cpe:2.3:a:ibm:db2:9.5


Contact Us

Shodan ® - All rights reserved