First published: Fri Dec 12 2014(Updated: )
IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying an identity column within a crafted ALTER TABLE statement.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.5 | |
IBM Db2 | =9.7 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6209 has a severity rating that indicates it can cause a denial of service condition.
To fix CVE-2014-6209, apply the latest fix pack updates to the affected IBM DB2 versions.
CVE-2014-6209 affects remote authenticated users of IBM DB2 versions 9.5, 9.7, 10.1, and 10.5 on Linux, UNIX, and Windows.
CVE-2014-6209 is a denial of service vulnerability that allows a crash of the daemon.
The attack vector for CVE-2014-6209 involves sending a crafted ALTER TABLE statement specifying an identity column.