Lucene search

K
cveIbmCVE-2012-4826
HistoryOct 20, 2012 - 10:41 a.m.

CVE-2012-4826

2012-10-2010:41:27
CWE-119
ibm
web.nvd.nist.gov
291
cve-2012-4826
buffer overflow
ibm db2
sql/psm
sp
security vulnerability
remote code execution

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.121

Percentile

95.4%

Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.

Affected configurations

Nvd
Node
ibmdb2Match9.1
OR
ibmdb2Match9.5
OR
ibmdb2Match9.7
OR
ibmdb2Match9.7.0.1
OR
ibmdb2Match9.7.0.2
OR
ibmdb2Match9.7.0.3
OR
ibmdb2Match9.7.0.4
OR
ibmdb2Match9.7.0.5
OR
ibmdb2Match9.7.0.6
OR
ibmdb2Match9.8
OR
ibmdb2Match10.1
VendorProductVersionCPE
ibmdb29.1cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:*
ibmdb29.5cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:*
ibmdb29.7cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
ibmdb29.7.0.1cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:*:*:*:*
ibmdb29.7.0.2cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:*:*:*:*
ibmdb29.7.0.3cpe:2.3:a:ibm:db2:9.7.0.3:*:*:*:*:*:*:*
ibmdb29.7.0.4cpe:2.3:a:ibm:db2:9.7.0.4:*:*:*:*:*:*:*
ibmdb29.7.0.5cpe:2.3:a:ibm:db2:9.7.0.5:*:*:*:*:*:*:*
ibmdb29.7.0.6cpe:2.3:a:ibm:db2:9.7.0.6:*:*:*:*:*:*:*
ibmdb29.8cpe:2.3:a:ibm:db2:9.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.121

Percentile

95.4%