IBM solidDB Stored Procedure Call Remote Denial of Service

low Nessus Plugin ID 66351

Synopsis

The remote host has a database server installed that is affected by a remote denial of service vulnerability.

Description

The version of IBM solidDB installed on the remote host is 6.5.x prior to 6.5.0.12, 6.30.x prior to 6.30.0.55, 6.0.x prior to 6.0.0.1070, or 7.0.x prior to 7.0.0.4. It therefore is reportedly affected by a remote denial of service vulnerability that can be triggered by calling a stored procedure with an omitted default value parameter.

Solution

Upgrade solidDB to version 6.0.0.1070 / 6.30.0.55 / 6.5.0.12 / 7.0.0.4 or later.

See Also

http://www-01.ibm.com/support/docview.wss?uid=swg1IC94043

http://www-01.ibm.com/support/docview.wss?uid=swg1IC94044

http://www-01.ibm.com/support/docview.wss?uid=swg1IC88796

http://www-01.ibm.com/support/docview.wss?uid=swg1IC88797

https://www-304.ibm.com/support/docview.wss?uid=swg21643599

http://www.nessus.org/u?64f69819

http://www.nessus.org/u?24195ffd

Plugin Details

Severity: Low

ID: 66351

File Name: soliddb_stored_procedure_dos.nasl

Version: 1.9

Type: local

Agent: windows

Family: Databases

Published: 5/8/2013

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Low

Base Score: 3.5

Temporal Score: 2.6

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:N/A:P

CVSS Score Source: CVE-2013-3031

Vulnerability Information

CPE: cpe:/a:ibm:soliddb

Required KB Items: SMB/solidDB/installed

Exploit Ease: No known exploits are available

Patch Publication Date: 12/5/2012

Vulnerability Publication Date: 12/5/2012

Reference Information

CVE: CVE-2013-3031

BID: 59637