Vulnerability Description
IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.
CVSS Score
7.5
HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 | 8.2_fixpack15 |
Related Weaknesses (CWE)
References
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APA
- http://secunia.com/advisories/28771Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ07337
- http://www.vupen.com/english/advisories/2008/0401
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APA
- http://secunia.com/advisories/28771Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ07337
- http://www.vupen.com/english/advisories/2008/0401
FAQ
What is CVE-2008-0696?
CVE-2008-0696 is a vulnerability with a CVSS score of 7.5 (HIGH). IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.
How severe is CVE-2008-0696?
CVE-2008-0696 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0696?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2.