CVE-2007-3676: Critical severity ibm db2 universal database vulnerability
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3676?
CVE-2007-3676 has a high severity level due to its potential for remote denial of service and arbitrary code execution.
How do I fix CVE-2007-3676?
To fix CVE-2007-3676, upgrade to IBM DB2 UDB Administration Server version 8 Fix Pack 16 or 9 Fix Pack 4 or later.
What software is affected by CVE-2007-3676?
CVE-2007-3676 affects IBM DB2 UDB Administration Server versions prior to Fix Pack 16 for 8.0 and Fix Pack 4 for 9.0.
What type of attack exploits CVE-2007-3676?
CVE-2007-3676 can be exploited through modified pointer values in remote administration requests, leading to system crashes.
Can CVE-2007-3676 result in data loss?
While CVE-2007-3676 primarily leads to denial of service, it could potentially result in data loss if exploited during sensitive operations.