First published: Sat Nov 08 2014(Updated: )
IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.7 | |
IBM Db2 | =9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6097 is considered a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2014-6097, upgrade to IBM DB2 versions 9.7 FP10 or 9.8 FP6 or later.
CVE-2014-6097 affects IBM DB2 versions 9.7 prior to FP10 and 9.8 up to FP5 on Linux, UNIX, and Windows.
Yes, CVE-2014-6097 can be exploited remotely by authenticated users via a specially crafted ALTER TABLE statement.
Exploiting CVE-2014-6097 can lead to a denial of service by causing the DB2 daemon to crash.