CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
AI Score
Confidence
Low
EPSS
Percentile
76.7%
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces “repeating” return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | db2 | 9.5 | cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:* |
ibm | db2 | 9.5 | cpe:2.3:a:ibm:db2:9.5:fp1:*:*:*:*:*:* |
ibm | db2 | 9.5 | cpe:2.3:a:ibm:db2:9.5:fp2:*:*:*:*:*:* |
ibm | db2 | 9.5 | cpe:2.3:a:ibm:db2:9.5:fp2a:*:*:*:*:*:* |
ibm | db2 | 9.5 | cpe:2.3:a:ibm:db2:9.5:fp3:*:*:*:*:*:* |
ibm | db2 | 9.5 | cpe:2.3:a:ibm:db2:9.5:fp3a:*:*:*:*:*:* |
ibm | db2 | 9.5 | cpe:2.3:a:ibm:db2:9.5:fp3b:*:*:*:*:*:* |
ibm | db2 | 9.7 | cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:* |
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT
secunia.com/advisories/37759
www-01.ibm.com/support/docview.wss?uid=swg1IC63946
www-01.ibm.com/support/docview.wss?uid=swg1IZ44872
www-01.ibm.com/support/docview.wss?uid=swg21293566
www-01.ibm.com/support/docview.wss?uid=swg21412902
www.securityfocus.com/bid/37332
www.vupen.com/english/advisories/2009/3520