icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

IBM DB2 9 < Fix Pack 5 Multiple Vulnerabilities

Synopsis

The remote IBM DB2 database server is affected by multiple vulnerabilities.

Description

According to its version, the installation of IBM DB2 on the remote host is affected by one or more of the following vulnerabilities :

- There is an unspecified security vulnerability related to a 'DB2FMP' process (IZ20352). - There is an unspecified security vulnerability in a CLR-stored procedure deployment from IBM Database Add-Ins for Visual Studio (JR28432). - The password used to connect to the database can be seen in plaintext in a memory dump (JR27422). - There is a possible stack variable overrun in 'SQLRLAKA()' (IZ16346). - A local privilege escalation vulnerability via file creation can result in root-level access (IZ12735). - There are possible buffer overflows involving 'XQUERY', 'XMLQUERY', 'XMLEXISTS', and 'XMLTABLE' (IZ18434).

Solution

Upgrade to IBM DB2 9.1 Fix Pack 6 or higher.