CVE-2012-2197
Summary
| CVE | CVE-2012-2197 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-25 10:42:34 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 9.1 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.10 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.11 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.2 | a | All | All |
| Application | Ibm | Db2 | 9.1.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.1.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.4 | a | All | All |
| Application | Ibm | Db2 | 9.1.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.6 | a | All | All |
| Application | Ibm | Db2 | 9.1.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.7 | a | All | All |
| Application | Ibm | Db2 | 9.1.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.1.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | b | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.6 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.securityfocus.com/bid/54487 | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www-01.ibm.com/support/docview.wss | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IC84555: SECURITY: STACK BUFFER OVERFLOW VULNERABILITY IN JAVA STORED PROCEDURE INFRASTRUCTURE (CVE-2012-2197). | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IC84752: SECURITY: STACK BUFFER OVERFLOW VULNERABILITY IN JAVA STORED PROCEDURE INFRASTRUCTURE (CVE-2012-2197). | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IC84755: SECURITY: STACK BUFFER OVERFLOW VULNERABILITY IN JAVA STORED PROCEDURE INFRASTRUCTURE (CVE-2012-2197). | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Security Vulnerabilities, HIPER and Special Attention APARs fixed in DB2 for Linux, UNIX, and Windows Version 9.1 Fix Pack 12 | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IC84753: SECURITY: STACK BUFFER OVERFLOW VULNERABILITY IN JAVA STORED PROCEDURE INFRASTRUCTURE (CVE-2012-2197). | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.