First published: Thu Dec 18 2014(Updated: )
IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted XML query.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.5 | |
IBM Db2 | =9.7 | |
IBM Db2 | =9.8 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8901 is classified as a denial of service vulnerability that can lead to significant CPU consumption.
To fix CVE-2014-8901, you should apply the latest patches or updates provided by IBM for your specific version of DB2.
CVE-2014-8901 affects IBM DB2 versions 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5.
CVE-2014-8901 can be exploited by remote authenticated users who send crafted XML queries to the vulnerable DB2 instances.
The impact of CVE-2014-8901 is a denial of service that results in excessive CPU usage, potentially degrading the performance of the database.