← Vulnerability feed

Vulnerability record · CVE-2009-3473 · published 29 September 2009

CVE-2009-3473: Ibm db2 vulnerability

Ibm · Db2

IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.

10.0 CVSS 2.0 High EPSS 2.0% · top 19.8%
10.0CVSS 2.0 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3473 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-1797Ibm db2 permissions and access controls vulnerabilityIBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.EPSS 1.7%10.0CVE-2010-3731Ibm db2 memory buffer overflow vulnerabilityStack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration …EPSS 9.6%10.0CVE-2010-3193Ibm db2 vulnerabilityUnspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.EPSS 2.7%10.0CVE-2009-4335Ibm db2 vulnerabilityMultiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and…EPSS 2.3%10.0CVE-2008-6820Ibm db2 vulnerabilityThe db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and att…EPSS 1.8%10.0CVE-2008-6821Ibm db2 memory buffer overflow vulnerabilityBuffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cau…EPSS 3.7%10.0CVE-2008-4692Ibm db2 vulnerabilityThe Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, …EPSS 2.1%10.0CVE-2007-3676Ibm db2 vulnerabilityIBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial o…EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2009-3473), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.