CVE-2014-3095
Summary
| CVE | CVE-2014-3095 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-04 10:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:S/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | a | All | All |
| Application | Ibm | Db2 | 10.1.0.4 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.10 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | b | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.6 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | a | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.5 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple IBM DB2 Products CVE-2014-3095 Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IT02433: SECURITY: DB2 contains a denial of service vulnerability in SQL Compiler (CVE-2014-3095) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| www-01.ibm.com/support/docview.wss | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Security Bulletin: IBM® DB2® LUW contains a denial of service vulnerability using a SELECT statement with a subquery containing a UNION (CVE-2014-3095) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM IT02645: SECURITY: DB2 contains a denial of service vulnerability in SQL Compiler (CVE-2014-3095) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Security Bulletin: IBM® InfoSphere Balanced Warehouse, IBM Smart Analytics System and IBM PureData System for Operational Analytics are affected by an IBM DB2® LUW denial of service vulnerability (CVE-2014-3095) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM IT02646: SECURITY: DB2 contains a denial of service vulnerability in SQL Compiler (CVE-2014-3095) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Security Advisory SA60845 - IBM DB2 / DB2 Connect Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www-01.ibm.com/support/docview.wss | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.