Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-0699

Overview

Vulnerability Score 9.0 9.0
CVE Id CVE-2008-0699
Last Modified 07 Apr 2011 12:00:00
Published 11 Feb 2008 08:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2008-0699

Summary

Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.

Vulnerable Systems

Application

  • Ibm Db2 8.2 Fixpack15

  • Ibm Db2 9.1

  • Ibm Db2 9.5


References

MISC - http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml

AIXAPAR - IZ10917

AIXAPAR - IZ06973

AIXAPAR - IZ06972

VUPEN - ADV-2008-0401

BUGTRAQ - 20080418 Team SHATTER Security Advisory: IBM DB2 UDB Arbitrary code execution in ADMIN_SP_C/ADMIN_SP_C2 procedures

SECUNIA - 29784

SECUNIA - 29022

SECUNIA - 28771

OSVDB - 41795

CONFIRM - ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT


Last Updated: 27 May 2016 10:46:54