IBM solidDB Stored Procedure Call Remote Denial of Service

Low Nessus Plugin ID 66351

Synopsis

The remote host has a database server installed that is affected by a remote denial of service vulnerability.

Description

The version of IBM solidDB installed on the remote host is 6.5.x prior to 6.5.0.12, 6.30.x prior to 6.30.0.55, 6.0.x prior to 6.0.0.1070, or 7.0.x prior to 7.0.0.4. It therefore is reportedly affected by a remote denial of service vulnerability that can be triggered by calling a stored procedure with an omitted default value parameter.

Solution

Upgrade solidDB to version 6.0.0.1070 / 6.30.0.55 / 6.5.0.12 / 7.0.0.4 or later.

See Also

http://www-01.ibm.com/support/docview.wss?uid=swg1IC94043

http://www-01.ibm.com/support/docview.wss?uid=swg1IC94044

http://www-01.ibm.com/support/docview.wss?uid=swg1IC88796

http://www-01.ibm.com/support/docview.wss?uid=swg1IC88797

https://www-304.ibm.com/support/docview.wss?uid=swg21643599

http://www.nessus.org/u?64f69819

http://www.nessus.org/u?24195ffd

Plugin Details

Severity: Low

ID: 66351

File Name: soliddb_stored_procedure_dos.nasl

Version: 1.7

Type: local

Family: Databases

Published: 2013/05/08

Updated: 2019/11/27

Dependencies: 31680, 53811

Risk Information

Risk Factor: Low

CVSS Score Source: CVE-2013-3031

CVSS v2.0

Base Score: 3.5

Temporal Score: 2.6

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:N/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:soliddb

Required KB Items: SMB/solidDB/installed

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2012/12/05

Vulnerability Publication Date: 2012/12/05

Reference Information

CVE: CVE-2013-3031

BID: 59637