9

CVE-2008-1997

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE-2008-0699.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 8.0 Update -
Ibm ≫ Db2 Version 8.0 Update fixpak1
Ibm ≫ Db2 Version 8.0 Update fixpak10
Ibm ≫ Db2 Version 8.0 Update fixpak11
Ibm ≫ Db2 Version 8.0 Update fixpak12
Ibm ≫ Db2 Version 8.0 Update fixpak13
Ibm ≫ Db2 Version 8.0 Update fixpak14
Ibm ≫ Db2 Version 8.0 Update fixpak15
Ibm ≫ Db2 Version 8.0 Update fixpak2
Ibm ≫ Db2 Version 8.0 Update fixpak3
Ibm ≫ Db2 Version 8.0 Update fixpak4
Ibm ≫ Db2 Version 8.0 Update fixpak5
Ibm ≫ Db2 Version 8.0 Update fixpak6
Ibm ≫ Db2 Version 8.0 Update fixpak6a
Ibm ≫ Db2 Version 8.0 Update fixpak6b
Ibm ≫ Db2 Version 8.0 Update fixpak6c
Ibm ≫ Db2 Version 8.0 Update fixpak7
Ibm ≫ Db2 Version 8.0 Update fixpak7a
Ibm ≫ Db2 Version 8.0 Update fixpak7b
Ibm ≫ Db2 Version 8.0 Update fixpak8
Ibm ≫ Db2 Version 8.0 Update fixpak8a
Ibm ≫ Db2 Version 8.0 Update fixpak9
Ibm ≫ Db2 Version 8.0 Update fixpak9a
Ibm ≫ Db2 Version 9.1 Update -
Ibm ≫ Db2 Version 9.1 Update fp1
Ibm ≫ Db2 Version 9.1 Update fp2
Ibm ≫ Db2 Version 9.1 Update fp2a
Ibm ≫ Db2 Version 9.1 Update fp3
Ibm ≫ Db2 Version 9.1 Update fp3a
Ibm ≫ Db2 Version 9.1 Update fp4
Ibm ≫ Db2 Version 9.5 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.43% 0.901
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://secunia.com/advisories/29022
Not Applicable
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06972
Vendor Advisory
http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml
Not Applicable
http://www.securityfocus.com/archive/1/491075/100/0/threaded
Third Party Advisory
VDB Entry
http://securityreason.com/securityalert/3841
Third Party Advisory
Issue Tracking