CVE-2014-3095
Summary
| CVE | CVE-2014-3095 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-04 10:55:00 UTC |
| Updated | 2017-08-29 01:34:00 UTC |
| Description | The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | a | All | All |
| Application | Ibm | Db2 | 10.1.0.4 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.10 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | b | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.6 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | a | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.5 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | a | All | All |
| Application | Ibm | Db2 | 10.1.0.4 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.10 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.2 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.3 | b | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.4 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.6 | a | All | All |
| Application | Ibm | Db2 | 9.5.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.5.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | a | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.5 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IT02643 | AIXAPAR | www-01.ibm.com | |
| IBM IT02645: SECURITY: DB2 contains a denial of service vulnerability in SQL Compiler (CVE-2014-3095) - United States | AIXAPAR | www-01.ibm.com | |
| About Secunia Research | Flexera | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM Security Bulletin: IBM® DB2® LUW contains a denial of service vulnerability using a SELECT statement with a subquery containing a UNION (CVE-2014-3095) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| Security Bulletin: IBM® InfoSphere Balanced Warehouse, IBM Smart Analytics System and IBM PureData System for Operational Analytics are affected by an IBM DB2® LUW denial of service vulnerability (CVE-2014-3095) | CONFIRM | www-01.ibm.com | |
| IT02644 | AIXAPAR | www-01.ibm.com | |
| Multiple IBM DB2 Products CVE-2014-3095 Remote Denial of Service Vulnerability | BID | www.securityfocus.com | |
| IT02433: SECURITY: DB2 contains a denial of service vulnerability in SQL Compiler (CVE-2014-3095) | AIXAPAR | www-01.ibm.com | Vendor Advisory |
| IBM IT02646: SECURITY: DB2 contains a denial of service vulnerability in SQL Compiler (CVE-2014-3095) - United States | AIXAPAR | www-01.ibm.com | |
| Security Advisory SA60845 - IBM DB2 / DB2 Connect Multiple Vulnerabilities - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.