InfoSphere BigInsights Big SQL contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with ROUND or TRUNCATE function. The vulnerability exists in the IBM DB2 component included in BigInsights that is used by the Big SQL server.
CVEID: CVE-2015-0157** **
DESCRIPTION: IBM DB2 LUW contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with ROUND or TRUNCATE function.
CVSS Base Score: 6.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100795 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C)
Effective CVSS Score: (score will update after page submission)
6.80
IBM InfoSphere BigInsights: 3.0, 3.0.0.1, 3.0.0.2
Apply iFix located on Fix Central.
Interim fix: IM-BigInsights-BigSQL-linuxamd64_CVE-2015-0157