CVE-2006-4257: Medium severity IBM DB2 vulnerability
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4257?
CVE-2006-4257 has a moderate severity rating due to its potential to cause denial of service.
How do I fix CVE-2006-4257?
To fix CVE-2006-4257, you should upgrade IBM DB2 Universal Database to version 8.1 FixPak 13 or later.
Who is affected by CVE-2006-4257?
CVE-2006-4257 affects IBM DB2 Universal Database versions before 8.1 FixPak 13 across various operating systems.
What are the exploitation vectors for CVE-2006-4257?
Exploitation of CVE-2006-4257 can occur by sending malformed ACCSEC commands or crafted SQLJRA packets during the CONNECT process.
Is CVE-2006-4257 remotely exploitable?
Yes, CVE-2006-4257 can be exploited by remote authenticated users.