CVE-2010-3731
Summary
| CVE | CVE-2010-3731 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-10-05 18:00:32 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.5 | fp1 | All | All |
| Application | Ibm | Db2 | 9.5 | fp2 | All | All |
| Application | Ibm | Db2 | 9.5 | fp2a | All | All |
| Application | Ibm | Db2 | 9.5 | fp3 | All | All |
| Application | Ibm | Db2 | 9.5 | fp3a | All | All |
| Application | Ibm | Db2 | 9.5 | fp3b | All | All |
| Application | Ibm | Db2 | 9.5 | fp4 | All | All |
| Application | Ibm | Db2 | 9.5 | fp4a | All | All |
| Application | Ibm | Db2 | 9.5 | fp5 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT | af854a3a-2127-422b-91ae-364da2661108 | public.dhe.ibm.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM IC70538: SECURITY: REMOTE BUFFER OVERFLOW VULNERABILITY IN DB2 ADMINISTRATIVE SERVER - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| IBM - Security Vulnerabilities and HIPER APARs fixed in DB2 for Linux, UNIX, and Windows Version 9.1 Fix Pack 9 | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM IC70539: SECURITY: REMOTE BUFFER OVERFLOW VULNERABILITY IN DB2 ADMINISTRATIVE SERVER - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM DB2 Administration Server "validateUser()" Buffer Overflow Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM DB2 Administration Server (DAS) 'validateUser()' Stack Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM IC69986: SECURITY: REMOTE BUFFER OVERFLOW VULNERABILITY IN DB2 ADMINISTRATIVE SERVER - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.