CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
51.7%
The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite “external memory” via unknown vectors, related to a missing “check for null pointers.”
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:*:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp1:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp10:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp11:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp12:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp13:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp14:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp15:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp16:*:*:*:*:*:* |
ibm | db2 | 8.2 | cpe:2.3:a:ibm:db2:8.2:fp17:*:*:*:*:*:* |
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT
secunia.com/advisories/37759
www-01.ibm.com/support/docview.wss?uid=swg1IC64702
www-01.ibm.com/support/docview.wss?uid=swg1LI72709
www-01.ibm.com/support/docview.wss?uid=swg1LI74500
www-01.ibm.com/support/docview.wss?uid=swg1LI74504
www-01.ibm.com/support/docview.wss?uid=swg21293566
www-01.ibm.com/support/docview.wss?uid=swg21412902
www.securityfocus.com/bid/37332
www.vupen.com/english/advisories/2009/3520