Title: IBM DB2 Prior to 8.1 Fixpack 18 Multiple Security Vulnerabilities
Severity: HIGH
Description:
IBM DB2 is a database manager.
The application is prone to multiple remote vulnerabilities:
1. A security-bypass issue occurs while handling the 'DAS' command. A local attacker can exploit this issue to gain unauthorized access.
2. A denial-of-service vulnerability in the 'DB2JDS' service occurs when handling crafted network packets. Specifically, the software fails to sufficiently validate data supplied as a string length when performing a UNICODE to ASCII string conversion. This issue affects the 'jdbcReadString()' function of the vulnerable service. A remote attacker can exploit this issue to crash the affected service.
3. An unspecified security issue can cause a UNIX-specific private memory leak.
Successful exploits of these issues may allow an attacker to bypass certain security restrictions or cause denial-of-service conditions.
These issues affect versions prior to IBM DB2 8 FixPak 18.
Affected Products:
- IBM DB2 Universal Database 8.0
- IBM DB2 Universal Database 8.0.0 FixPak 16
- IBM DB2 Universal Database 8.0.0 FixPak 17
- IBM DB2 Universal Database 8.1
- IBM DB2 Universal Database 8.1 FixPak 15
- IBM DB2 Universal Database 8.1 FixPak 17a
- IBM DB2 Universal Database 8.2
- IBM DB2 Universal Database 8.2 FixPak 8
References:
- IBM: DB2 UDB Version 8.1 FixPak 18 (also known as Version 8.2 FixPak 11)
- IBM: IBM DB2 Homepage
- IBM: IZ52433: SECURITY: MALICIOUS PACKETS CAUSE DB2JDS TO CRASH.
- NSFOCUS: NSFOCUS - IBM DB2 JDBC Applet Server Remote DoS Vulnerability(SA2009-02)
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.