IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
| Software | From | Fixed in |
|---|---|---|
| ibm / db2 | 9.5 | 9.5.x |
| ibm / db2 | 9.5-fp4 | 9.5-fp4.x |
| ibm / db2 | 9.5-fp5 | 9.5-fp5.x |
| ibm / db2 | 9.5-fp4a | 9.5-fp4a.x |
| ibm / db2 | 9.5-fp1 | 9.5-fp1.x |
| ibm / db2 | 9.5-fp2a | 9.5-fp2a.x |
| ibm / db2 | 9.5-fp6 | 9.5-fp6.x |
| ibm / db2 | - | 9.5.x |
| ibm / db2 | 9.5-fp3b | 9.5-fp3b.x |
| ibm / db2 | 9.5-fp2 | 9.5-fp2.x |
| ibm / db2 | 9.5-fp3 | 9.5-fp3.x |
| ibm / db2 | 9.5-fp3a | 9.5-fp3a.x |
| ibm / db2 | 9.7-fp1 | 9.7-fp1.x |
| ibm / db2 | - | 9.7.x |
| ibm / db2 | 9.7-fp2 | 9.7-fp2.x |
| ibm / db2 | 9.7 | 9.7.x |