First published: Wed Jul 25 2012(Updated: )
Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1.0.1 | |
IBM DB2 Universal Database | =9.1.0.2 | |
IBM DB2 Universal Database | =9.1.0.2-a | |
IBM DB2 Universal Database | =9.1.0.3 | |
IBM DB2 Universal Database | =9.1.0.3-a | |
IBM DB2 Universal Database | =9.1.0.4 | |
IBM DB2 Universal Database | =9.1.0.4-a | |
IBM DB2 Universal Database | =9.1.0.5 | |
IBM DB2 Universal Database | =9.1.0.6 | |
IBM DB2 Universal Database | =9.1.0.6-a | |
IBM DB2 Universal Database | =9.1.0.7 | |
IBM DB2 Universal Database | =9.1.0.7-a | |
IBM DB2 Universal Database | =9.1.0.8 | |
IBM DB2 Universal Database | =9.1.0.9 | |
IBM DB2 Universal Database | =9.1.0.10 | |
IBM DB2 Universal Database | =9.1.0.11 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5.0.1 | |
IBM DB2 Universal Database | =9.5.0.2 | |
IBM DB2 Universal Database | =9.5.0.2-a | |
IBM DB2 Universal Database | =9.5.0.3 | |
IBM DB2 Universal Database | =9.5.0.3-a | |
IBM DB2 Universal Database | =9.5.0.3-b | |
IBM DB2 Universal Database | =9.5.0.4 | |
IBM DB2 Universal Database | =9.5.0.4-a | |
IBM DB2 Universal Database | =9.5.0.5 | |
IBM DB2 Universal Database | =9.5.0.6-a | |
IBM DB2 Universal Database | =9.5.0.7 | |
IBM DB2 Universal Database | =9.5.0.8 | |
IBM DB2 Universal Database | =9.5.0.9 | |
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =9.7.0.1 | |
IBM DB2 Universal Database | =9.7.0.2 | |
IBM DB2 Universal Database | =9.7.0.3 | |
IBM DB2 Universal Database | =9.7.0.4 | |
IBM DB2 Universal Database | =9.7.0.5 | |
IBM DB2 Universal Database | =9.7.0.6 | |
IBM DB2 Universal Database | =9.8 | |
IBM DB2 Universal Database | =9.8.0.3 | |
IBM DB2 Universal Database | =9.8.0.4 | |
IBM DB2 Universal Database | =9.8.0.5 | |
IBM DB2 Universal Database | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2197 has a high severity rating due to the potential for remote authenticated users to execute arbitrary code.
To fix CVE-2012-2197, upgrade IBM DB2 to an appropriate version that includes the necessary security patches.
CVE-2012-2197 affects IBM DB2 versions 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1.
The potential impacts of CVE-2012-2197 include unauthorized execution of arbitrary code, which could compromise the database and the information it holds.
CVE-2012-2197 can be exploited by remote authenticated users who have specific CONNECT and EXECUTE privileges.