CVE-2010-3731: Buffer Overflow
Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3731?
CVE-2010-3731 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2010-3731?
To fix CVE-2010-3731, install the latest fix pack for IBM DB2 that addresses this vulnerability.
What versions of IBM DB2 are affected by CVE-2010-3731?
CVE-2010-3731 affects IBM DB2 versions 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3.
Can CVE-2010-3731 be exploited remotely?
Yes, CVE-2010-3731 can be exploited remotely, allowing attackers to execute arbitrary code.
Is there a patch available for CVE-2010-3731?
Yes, IBM has released patches in fix packs that address CVE-2010-3731.