5

CVE-2008-3959

IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Update fp15 Version <= 8.1
Ibm ≫ Db2 Update fp8 Version <= 8.2
Ibm ≫ Db2 Version 8.1 Update fp1
Ibm ≫ Db2 Version 8.1 Update fp10
Ibm ≫ Db2 Version 8.1 Update fp11
Ibm ≫ Db2 Version 8.1 Update fp12
Ibm ≫ Db2 Version 8.1 Update fp13
Ibm ≫ Db2 Version 8.1 Update fp14
Ibm ≫ Db2 Version 8.1 Update fp2
Ibm ≫ Db2 Version 8.1 Update fp3
Ibm ≫ Db2 Version 8.1 Update fp4
Ibm ≫ Db2 Version 8.1 Update fp5
Ibm ≫ Db2 Version 8.1 Update fp6
Ibm ≫ Db2 Version 8.1 Update fp7
Ibm ≫ Db2 Version 8.1 Update fp8
Ibm ≫ Db2 Version 8.1 Update fp9
Ibm ≫ Db2 Version 8.2
Ibm ≫ Db2 Version 8.2 Update fp1
Ibm ≫ Db2 Version 8.2 Update fp2
Ibm ≫ Db2 Version 8.2 Update fp3
Ibm ≫ Db2 Version 8.2 Update fp4
Ibm ≫ Db2 Version 8.2 Update fp5
Ibm ≫ Db2 Version 8.2 Update fp6
Ibm ≫ Db2 Version 8.2 Update fp7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.19% 0.801
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/29022
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ05043
Patch
http://www.appsecinc.com/resources/alerts/db2/2008-01.shtml
https://exchange.xforce.ibmcloud.com/vulnerabilities/45134