First published: Tue Feb 01 2011(Updated: )
Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp6a | |
IBM DB2 Universal Database | =9.1-fp1 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp5 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp7a | |
IBM DB2 Universal Database | =9.1-fp3a | |
IBM DB2 Universal Database | =9.1-fp2a | |
IBM DB2 Universal Database | =9.1-fp6 | |
IBM DB2 Universal Database | <=9.1 | |
IBM DB2 Universal Database | =9.1-fp8 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1-fp7 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5-fp4 | |
IBM DB2 Universal Database | =9.5-fp5 | |
IBM DB2 Universal Database | =9.5-fp4a | |
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.5-fp2a | |
IBM DB2 Universal Database | =9.5-fp6 | |
IBM DB2 Universal Database | <=9.5 | |
IBM DB2 Universal Database | =9.5-fp3b | |
IBM DB2 Universal Database | =9.5-fp2 | |
IBM DB2 Universal Database | =9.5-fp3 | |
IBM DB2 Universal Database | =9.5-fp3a | |
IBM DB2 Universal Database | <=9.7 | |
IBM DB2 Universal Database | =9.7-fp1 | |
IBM DB2 Universal Database | =9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0731 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2011-0731, you should update IBM DB2 to the latest version or apply the relevant fix pack.
IBM DB2 versions 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows are affected by CVE-2011-0731.
Yes, CVE-2011-0731 can be exploited remotely, allowing attackers to execute arbitrary code.
The potential impacts of CVE-2011-0731 include unauthorized access, data manipulation, and complete system compromise.