J-Security Center

Title: IBM DB2 CLR Stored Procedures Deployment Unspecified Vulnerability

Severity: MODERATE

Description:

IBM DB2 is a Database Management System.

IBM DB2 is prone to an unspecified security vulnerability that occurs when deploying CLR stored procedures from IBM Database Add-ins for Visual Studio.

Very little is known about this issue at this time. We will update this BID as more information emerges.

Versions prior to IBM DB2 9.5 Fixpak 2 are vulnerable.

Affected Products:

  • IBM DB2 Universal Database 9.1
  • IBM DB2 Universal Database 9.1 Fix Pack 4a
  • IBM DB2 Universal Database 9.5
  • IBM DB2 Universal Database 9.5 Fix Pack 1
  • IBM DB2 Universal Database for HP-UX 9.1
  • IBM DB2 Universal Database for HP-UX 9.1 FixPack 2
  • IBM DB2 Universal Database for HP-UX 9.1 FixPak 3
  • IBM DB2 Universal Database for HP-UX 9.1 FixPak 4
  • IBM DB2 Universal Database for HP-UX 9.1 FixPak 4a
  • IBM DB2 Universal Database for HP-UX 9.1 Fixpak 4
  • IBM DB2 Universal Database for HP-UX 9.1 Fixpak 5
  • IBM DB2 Universal Database for Linux 9.1
  • IBM DB2 Universal Database for Linux 9.1 FixPack 2
  • IBM DB2 Universal Database for Linux 9.1 FixPak 3
  • IBM DB2 Universal Database for Linux 9.1 FixPak 4
  • IBM DB2 Universal Database for Linux 9.1 FixPak 4a
  • IBM DB2 Universal Database for Linux 9.1 Fixpak 5
  • IBM DB2 Universal Database for Linux 9.5
  • IBM DB2 Universal Database for Linux 9.5 FixPak 1
  • IBM DB2 Universal Database for Windows 9.1
  • IBM DB2 Universal Database for Windows 9.1 FixPack 2
  • IBM DB2 Universal Database for Windows 9.1 FixPak 3
  • IBM DB2 Universal Database for Windows 9.1 FixPak 4
  • IBM DB2 Universal Database for Windows 9.1 Fixpak 5
  • IBM DB2 Universal Database for Windows 9.1Fix Pak 4a
  • IBM DB2 Universal Database for Windows 9.5
  • IBM DB2 Universal Database for Windows 9.5 Fix Pak 1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.