PT-2006-5068 · Ibm · Ibm Db2 Universal Database

Published

2006-08-21

·

Updated

2018-10-17

·

CVE-2006-4257

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM DB2 Universal Database (UDB) versions prior to 8.1 FixPak 13
Description The issue allows remote authenticated users to cause a denial of service by sending specific commands or packets, resulting in a crash. This can be achieved by either sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or by sending crafted SQLJRA packets, which leads to a null dereference.
Recommendations For versions prior to 8.1 FixPak 13, update to at least 8.1 FixPak 13 to resolve the issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-4257

Affected Products

Ibm Db2 Universal Database