CVE-2015-0157

MEDIUM

Description

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.

References

http://www-01.ibm.com/support/docview.wss?uid=swg1IT07103

http://www-01.ibm.com/support/docview.wss?uid=swg1IT07107

http://www-01.ibm.com/support/docview.wss?uid=swg1IT07108

http://www-01.ibm.com/support/docview.wss?uid=swg1IT07109

http://www-01.ibm.com/support/docview.wss?uid=swg21697987

http://www.securityfocus.com/bid/75947

http://www.securitytracker.com/id/1032882

Details

Source: MITRE

Published: 2015-07-20

Updated: 2017-09-22

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C)

Impact Score: 6.9

Exploitability Score: 8

Severity: MEDIUM