First published: Wed Dec 18 2013(Updated: )
The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.5 | |
IBM Db2 | =9.7 | |
IBM Db2 | =9.8 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.5 | |
IBM DB2 Connect | =9.5 | |
IBM DB2 Connect | =9.7 | |
IBM DB2 Connect | =9.8 | |
IBM DB2 Connect | =10.1 | |
IBM DB2 Connect | =10.5 | |
IBM DB2 pureScale Feature |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5466 is a denial-of-service vulnerability affecting multiple versions of IBM DB2 and DB2 Connect.
To remediate CVE-2013-5466, update your IBM DB2 or DB2 Connect to the latest patched version provided by IBM.
CVE-2013-5466 affects IBM DB2 versions 9.5 through 10.5 and IBM DB2 Connect versions 9.5 through 10.5.
No, CVE-2013-5466 requires the attacker to be a remote authenticated user to exploit the vulnerability.
Exploitation of CVE-2013-5466 can lead to significant service disruptions, impacting the availability of the affected DB2 systems.