vendor:
DB2 UDB Server
by:
Dennis Yurichev
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DB2 UDB Server
Affected Version From: 8.1/9.1
Affected Version To: 8.1/9.1
Patch Exists: YES
Related CWE: CVE-2009-0943
CPE: a:ibm:db2_udb_server:8.1
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
IBM DB2 UDB 8.1/9.1 Remote Buffer Overflow
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM DB2 UDB. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DB2TEST database. The issue lies in the handling of a specially crafted packet sent to the DB2TEST database. An attacker can leverage this vulnerability to execute arbitrary code under the context of the DB2 service.
Mitigation:
Upgrade to the latest version of IBM DB2 UDB 8.1/9.1