CVE-2011-1846

CVE-2011-1846

CVE-2011-1846 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.