IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/49864 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1JR31886 | patch vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21381257 | patch vendor advisory |
http://www.vupen.com/english/advisories/2009/0912 | vdb entry vendor advisory |