PT-2010-5034 · Ibm · Ibm Db2 Udb

Published

2010-10-05

·

Updated

2017-09-19

·

CVE-2010-3740

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM DB2 UDB version 9.5 before FP6a
Description The issue is related to the Net Search Extender implementation in the Text Search component, which does not properly handle an alphanumeric Fuzzy search. This allows remote authenticated users to cause a denial of service, resulting in memory consumption and system hang, via the db2ext.textSearch function.
Recommendations For IBM DB2 UDB version 9.5 before FP6a, update to FP6a or later to resolve the issue. As a temporary workaround, consider restricting access to the db2ext.textSearch function to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3740

Affected Products

Ibm Db2 Udb