CVE-2018-1977: Input Validation
Published Dec 14, 2018
·Updated
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with TRUNCATE function. IBM X-Force ID: 154032.
Affected Software
3 affected components
IBM DB2=11.1
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Dec 12, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1977?
CVE-2018-1977 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-1977?
To fix CVE-2018-1977, it's recommended to apply the latest patches provided by IBM for DB2 version 11.1.
3
Who is affected by CVE-2018-1977?
CVE-2018-1977 affects remote, authenticated users of IBM DB2 for Linux, UNIX, and Windows 11.1.
4
What is the exploit mechanism for CVE-2018-1977?
The vulnerability can be exploited by issuing a specially-crafted SELECT statement incorporating the TRUNCATE function.
5
Is there a workaround for CVE-2018-1977?
Currently, there are no documented workarounds available for mitigating CVE-2018-1977.