First published: Wed Oct 08 2003(Updated: )
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0837 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
To mitigate CVE-2003-0837, install Fixpak 10a or later for IBM DB2 Universal Database 7.2.
CVE-2003-0837 affects users of IBM DB2 Universal Database 7.2 for Windows prior to Fixpak 10a.
CVE-2003-0837 is caused by a stack-based buffer overflow in the INVOKE command functionality.
Yes, CVE-2003-0837 can be exploited by attackers with 'Connect' privileges remotely.