First published: Fri May 08 2015(Updated: )
IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =9.8 | |
IBM DB2 Universal Database | =9.8 | |
IBM DB2 Universal Database | =9.8 | |
IBM DB2 Universal Database | =9.8 | |
IBM DB2 Universal Database | =9.8 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.1 | |
IBM DB2 Universal Database | =10.5 | |
IBM DB2 Universal Database | =10.5 | |
IBM DB2 Universal Database | =10.5 | |
IBM DB2 Universal Database | =10.5 | |
IBM DB2 Universal Database | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0919 is rated as a medium severity vulnerability due to its potential to leak sensitive information.
To fix CVE-2014-0919, update IBM DB2 to the latest version that addresses this vulnerability.
CVE-2014-0919 affects IBM DB2 versions 9.5 through 10.5 on Linux, UNIX, and Windows platforms.
CVE-2014-0919 can expose sensitive password information stored during SQL statement processing.
Yes, CVE-2014-0919 can be exploited by remote authenticated users through monitoring and audit command facilities.