Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-1997

Overview

Vulnerability Score 9.0 9.0
CVE Id CVE-2008-1997
Last Modified 29 Jan 2009 01:48:55
Published 28 Apr 2008 04:05:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2008-1997

Summary

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE-2008-0699.

Vulnerable Systems

Application

  • Ibm Db2 Server


References

BUGTRAQ - 20080418 Team SHATTER Security Advisory: IBM DB2 UDB Arbitrary code execution in ADMIN_SP_C/ADMIN_SP_C2 procedures

MISC - http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml

AIXAPAR - IZ06972

SREASON - 3841

SECUNIA - 29022


Last Updated: 27 May 2016 10:47:43