IBM DB2 Universal Database JDBC Applet Server Unspecified Code Execution Vulnerability
BID:23890
Info
IBM DB2 Universal Database JDBC Applet Server Unspecified Code Execution Vulnerability
| Bugtraq ID: | 23890 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2582 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2007 12:00AM |
| Updated: | May 07 2015 05:39PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM DB2 Universal Database Win98/NT/2000 7.0 IBM DB2 Universal Database for Windows NT 7.1 IBM DB2 Universal Database for Windows NT 6.1 IBM DB2 Universal Database for Windows 8.12 IBM DB2 Universal Database for Windows 8.10 IBM DB2 Universal Database for Windows 8.2 IBM DB2 Universal Database for Windows 8.1.9 a IBM DB2 Universal Database for Windows 8.1.9 IBM DB2 Universal Database for Windows 8.1.8 a IBM DB2 Universal Database for Windows 8.1.8 IBM DB2 Universal Database for Windows 8.1.7 b IBM DB2 Universal Database for Windows 8.1.7 IBM DB2 Universal Database for Windows 8.1.6 c IBM DB2 Universal Database for Windows 8.1.6 IBM DB2 Universal Database for Windows 8.1.5 IBM DB2 Universal Database for Windows 8.1.4 IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 7.2 IBM DB2 Universal Database for Windows 7.1 IBM DB2 Universal Database for Windows 9.1 FixPack 2 IBM DB2 Universal Database for Windows 9.1 IBM DB2 Universal Database for Windows 9.0 Fix Pack 2 IBM DB2 Universal Database for Windows 8.2 FixPak 7 IBM DB2 Universal Database for Windows 8.1 FixPak 14 IBM DB2 Universal Database for Windows 8.0 FixPak 13 IBM DB2 Universal Database for Solaris 9.0 IBM DB2 Universal Database for Solaris 8.12 IBM DB2 Universal Database for Solaris 8.10 IBM DB2 Universal Database for Solaris 8.1.9 a IBM DB2 Universal Database for Solaris 8.1.9 IBM DB2 Universal Database for Solaris 8.1.8 a IBM DB2 Universal Database for Solaris 8.1.8 IBM DB2 Universal Database for Solaris 8.1.7 b IBM DB2 Universal Database for Solaris 8.1.7 IBM DB2 Universal Database for Solaris 8.1.6 c IBM DB2 Universal Database for Solaris 8.1.6 IBM DB2 Universal Database for Solaris 8.1.5 IBM DB2 Universal Database for Solaris 8.1.4 IBM DB2 Universal Database for Solaris 8.1 IBM DB2 Universal Database for Solaris 8.0 IBM DB2 Universal Database for Solaris 7.2 IBM DB2 Universal Database for Solaris 7.1 IBM DB2 Universal Database for Solaris 7.0 IBM DB2 Universal Database for Solaris 6.1 IBM DB2 Universal Database for Solaris 6.0 IBM DB2 Universal Database for Solaris 9.1 FixPack 2 IBM DB2 Universal Database for Solaris 9.1 IBM DB2 Universal Database for Solaris 9.0.0 Fixpak 1 IBM DB2 Universal Database for Solaris 9.0 Fix Pack 2 IBM DB2 Universal Database for Solaris 8.2 FixPak 7 IBM DB2 Universal Database for Solaris 8.1 FixPak 14 IBM DB2 Universal Database for Solaris 8.0 FixPak 13 IBM DB2 Universal Database for OS/390 and z/OS 8.0 IBM DB2 Universal Database for OS/390 and z/OS 7.1 IBM DB2 Universal Database for OS/390 and z/OS 6.0 IBM DB2 Universal Database for OS/390 and z/OS 5.0 IBM DB2 Universal Database for OS/390 and z/OS 8.1 FixPak 14 IBM DB2 Universal Database for OS/390 and z/OS 8.0 FixPak 13 IBM DB2 Universal Database for Linux 9.0 IBM DB2 Universal Database for Linux 8.12 IBM DB2 Universal Database for Linux 8.10 IBM DB2 Universal Database for Linux 8.2 IBM DB2 Universal Database for Linux 8.1.9 a IBM DB2 Universal Database for Linux 8.1.9 IBM DB2 Universal Database for Linux 8.1.8 a IBM DB2 Universal Database for Linux 8.1.8 IBM DB2 Universal Database for Linux 8.1.7 b IBM DB2 Universal Database for Linux 8.1.7 IBM DB2 Universal Database for Linux 8.1.6 c IBM DB2 Universal Database for Linux 8.1.6 IBM DB2 Universal Database for Linux 8.1.5 IBM DB2 Universal Database for Linux 8.1.4 IBM DB2 Universal Database for Linux 8.1 IBM DB2 Universal Database for Linux 8.0 IBM DB2 Universal Database for Linux 7.2 IBM DB2 Universal Database for Linux 7.1 IBM DB2 Universal Database for Linux 7.0 IBM DB2 Universal Database for Linux 6.1 IBM DB2 Universal Database for Linux 6.0 IBM DB2 Universal Database for Linux 9.1 FixPack 2 IBM DB2 Universal Database for Linux 9.1 IBM DB2 Universal Database for Linux 9.0.0 Fixpack 1 IBM DB2 Universal Database for Linux 9.0 Fix Pack 2 IBM DB2 Universal Database for Linux 8.2 FixPak 7 IBM DB2 Universal Database for Linux 8.1 FixPak 14 IBM DB2 Universal Database for Linux 8.0 FixPak 13 IBM DB2 Universal Database for HP-UX 9.0 IBM DB2 Universal Database for HP-UX 8.12 IBM DB2 Universal Database for HP-UX 8.10 IBM DB2 Universal Database for HP-UX 8.2 IBM DB2 Universal Database for HP-UX 8.1.9 a IBM DB2 Universal Database for HP-UX 8.1.9 IBM DB2 Universal Database for HP-UX 8.1.8 a IBM DB2 Universal Database for HP-UX 8.1.8 IBM DB2 Universal Database for HP-UX 8.1.7 b IBM DB2 Universal Database for HP-UX 8.1.7 IBM DB2 Universal Database for HP-UX 8.1.6 c IBM DB2 Universal Database for HP-UX 8.1.6 IBM DB2 Universal Database for HP-UX 8.1.5 IBM DB2 Universal Database for HP-UX 8.1.4 IBM DB2 Universal Database for HP-UX 8.1 IBM DB2 Universal Database for HP-UX 8.0 IBM DB2 Universal Database for HP-UX 7.2 IBM DB2 Universal Database for HP-UX 7.1 IBM DB2 Universal Database for HP-UX 7.0 IBM DB2 Universal Database for HP-UX 6.1 IBM DB2 Universal Database for HP-UX 6.0 IBM DB2 Universal Database for HP-UX 9.1 FixPack 2 IBM DB2 Universal Database for HP-UX 9.1 IBM DB2 Universal Database for HP-UX 9.0.0 Fixpak 1 IBM DB2 Universal Database for HP-UX 8.2 FixPak 7 IBM DB2 Universal Database for HP-UX 8.1 FixPak 14 IBM DB2 Universal Database for HP-UX 8.0 FixPak 13 IBM DB2 Universal Database for AIX 9.0 IBM DB2 Universal Database for AIX 8.12 IBM DB2 Universal Database for AIX 8.10 IBM DB2 Universal Database for AIX 8.2 IBM DB2 Universal Database for AIX 8.1.9 a IBM DB2 Universal Database for AIX 8.1.9 IBM DB2 Universal Database for AIX 8.1.8 a IBM DB2 Universal Database for AIX 8.1.8 IBM DB2 Universal Database for AIX 8.1.7 b IBM DB2 Universal Database for AIX 8.1.7 IBM DB2 Universal Database for AIX 8.1.6 c IBM DB2 Universal Database for AIX 8.1.6 IBM DB2 Universal Database for AIX 8.1.5 IBM DB2 Universal Database for AIX 8.1.4 IBM DB2 Universal Database for AIX 8.1 IBM DB2 Universal Database for AIX 8.0 IBM DB2 Universal Database for AIX 7.2 IBM DB2 Universal Database for AIX 7.1 IBM DB2 Universal Database for AIX 7.0 IBM DB2 Universal Database for AIX 6.1 IBM DB2 Universal Database for AIX 6.0 IBM DB2 Universal Database for AIX 9.1 FixPack 2 IBM DB2 Universal Database for AIX 9.1 IBM DB2 Universal Database for AIX 9.0.0 Fixpak 1 IBM DB2 Universal Database for AIX 9.0 Fix Pack 2 IBM DB2 Universal Database for AIX 8.2 FixPak 7 IBM DB2 Universal Database for AIX 8.1 FixPak 14 IBM DB2 Universal Database for AIX 8.0 FixPak 13 |
| Not Vulnerable: | |
Discussion
IBM DB2 Universal Database JDBC Applet Server Unspecified Code Execution Vulnerability
IBM DB2 Universal Database is prone to an unspecified remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the application. Successful attacks can result in the compromise of the application or can cause denial-of-service conditions.
This issue was fixed in fixpak 15 for v8.
IBM DB2 Universal Database is prone to an unspecified remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the application. Successful attacks can result in the compromise of the application or can cause denial-of-service conditions.
This issue was fixed in fixpak 15 for v8.
Exploit / POC
IBM DB2 Universal Database JDBC Applet Server Unspecified Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM DB2 Universal Database JDBC Applet Server Unspecified Code Execution Vulnerability
Solution:
This issue has been addressed by the vendor with fixpak 15 for v8. Please see the vendor references for more information.
Solution:
This issue has been addressed by the vendor with fixpak 15 for v8. Please see the vendor references for more information.
References
IBM DB2 Universal Database JDBC Applet Server Unspecified Code Execution Vulnerability
References:
References:
- DB APAR IY97750 (IBM)
- DB2 Universal Database Product Page (IBM)