MEDIUM · 6.4

CVE-2010-3739

The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in...

Vulnerability Description

The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
IbmDb2 Universal Database<= 9.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3739?

CVE-2010-3739 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in...

How severe is CVE-2010-3739?

CVE-2010-3739 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3739?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2 Universal Database.