PT-2015-2765 · Ibm · Ibm Db2

Igor

·

Publicado

2015-07-19

·

Atualizado

2017-09-22

·

CVE-2015-0157

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions IBM DB2 versions 9.7 through FP10 IBM DB2 versions 9.8 through FP5 IBM DB2 version 10.1 before FP5 IBM DB2 versions 10.5 through FP5
Description The issue is related to errors in the code of the IBM DB2 database management system. It can be exploited by a remote attacker to cause a denial of service by using a scalar function in an SQL query. This can lead to a daemon crash. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For IBM DB2 version 9.7, update to a version after FP10 to resolve the issue. For IBM DB2 version 9.8, update to a version after FP5 to resolve the issue. For IBM DB2 version 10.1, update to FP5 or later to resolve the issue. For IBM DB2 version 10.5, update to a version after FP5 to resolve the issue. As a temporary workaround, consider restricting the use of scalar functions in SQL statements until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-12130
CVE-2015-0157

Produtos afetados

Ibm Db2