Lucene search

K
ibmIBM3BBE4157B3F93213F492FD5830AD7280EA81A952E68D7FDBF038F98105FAE9ED
HistoryJul 18, 2020 - 11:17 p.m.

Security Bulletin: BigInsights is affected by a vulnerability in DB2 (CVE-2014-0919, CVE-2016-0211)

2020-07-1823:17:55
www.ibm.com
15

EPSS

0.042

Percentile

92.3%

Summary

BigInsights is affected by a vulnerability in DB2 (CVE-2014-0919, CVE-2016-0211).

Vulnerability Details

CVEID: CVE-2016-0211**
DESCRIPTION:** IBM DB2 LUW contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted DRDA message and cause DB2 server to terminate abnormally.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/109608 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2014-0919**
DESCRIPTION:** IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/91981
for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS: 4.0/AV:N/AC:L/Au:S/C:P/I:N/A:N)

Affected Products and Versions

IBM InfoSphere BigInsights: 3.0.0.2, 4.0, 4.1

Remediation/Fixes

Principal Product and Version(s)

| Fix
—|—
IBM InfoSphere BigInsights 4.x| Apply rpm from Fix Central: db2luw_4_1_0_2-10.6-0.3x86_64rhel6.rpm
IBM InfoSphere BigInsights: 3.0.0.2| Apply IFix from Fix Central: _ _
IM-BigInsights-EE-linuxamd64_DB2_malformatted_DRDA_messages

Workarounds and Mitigations

None

EPSS

0.042

Percentile

92.3%

Related for 3BBE4157B3F93213F492FD5830AD7280EA81A952E68D7FDBF038F98105FAE9ED