First published: Tue Jan 16 2018(Updated: )
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.7 | |
IBM Db2 | =9.7 | |
IBM Db2 | =9.7 | |
IBM Db2 | =9.7 | |
IBM Db2 for i | =9.7 | |
IBM Db2 for z/OS | =9.7 | |
IBM Db2 | =9.7 | |
IBM Db2 | =9.7 | |
IBM Db2 | =9.7 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.1 | |
IBM Db2 for i | =10.1 | |
IBM Db2 for z/OS | =10.1 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.1 | |
IBM Db2 | =10.5 | |
IBM Db2 | =10.5 | |
IBM Db2 | =10.5 | |
IBM Db2 | =10.5 | |
IBM Db2 for i | =10.5 | |
IBM Db2 for z/OS | =10.5 | |
IBM Db2 | =10.5 | |
IBM Db2 | =10.5 | |
IBM Db2 | =10.5 | |
HPE HP-UX | ||
IBM AIX | ||
Linux Kernel | ||
Microsoft Windows | ||
Oracle Solaris SPARC | ||
IBM Db2 | =9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0215 has a medium severity rating as it allows remote authenticated users to cause a denial of service.
To fix CVE-2016-0215, upgrade to IBM DB2 versions 9.7 FP6, 10.1 FP8, or newer.
IBM DB2 versions 9.7, 10.1 before FP6, and 10.5 before FP8 are affected by CVE-2016-0215.
CVE-2016-0215 can facilitate denial of service attacks against IBM DB2 databases.
Yes, CVE-2016-0215 affects IBM DB2 for i and z/OS versions that fall under the specified vulnerable versions.