CVE-2008-1997: Code Injection
Unspecified vulnerability in the ADMINSPC2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMINSPC issue is already covered by CVE-2008-0699.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1997?
The severity of CVE-2008-1997 is considered high due to the ability for remote authenticated users to execute arbitrary code.
How do I fix CVE-2008-1997?
To fix CVE-2008-1997, upgrade to IBM DB2 version 9.1 FP16, 9.5 FP1, or a later version to mitigate the vulnerability.
Which versions of IBM DB2 are affected by CVE-2008-1997?
CVE-2008-1997 affects IBM DB2 versions prior to 8 FP16, 9.1 FP4a, and 9.5 FP1.
Can CVE-2008-1997 lead to data breaches?
Yes, CVE-2008-1997 can potentially lead to data breaches as it allows execution of arbitrary code by an authenticated user.
What are the consequences of exploiting CVE-2008-1997?
Exploiting CVE-2008-1997 can result in unauthorized access and control over affected DB2 databases, leading to potential data compromise.