CVE Vulnerabilities

CVE-2008-2154

Published: Jun 03, 2009 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.

Affected Software

Name Vendor Start Version End Version
Db2 Ibm 8.0-fp1 (including) 8.0-fp1 (including)
Db2 Ibm 8.0-fp10 (including) 8.0-fp10 (including)
Db2 Ibm 8.0-fp11 (including) 8.0-fp11 (including)
Db2 Ibm 8.0-fp12 (including) 8.0-fp12 (including)
Db2 Ibm 8.0-fp13 (including) 8.0-fp13 (including)
Db2 Ibm 8.0-fp14 (including) 8.0-fp14 (including)
Db2 Ibm 8.0-fp15 (including) 8.0-fp15 (including)
Db2 Ibm 8.0-fp16 (including) 8.0-fp16 (including)
Db2 Ibm 9.1-fp1 (including) 9.1-fp1 (including)
Db2 Ibm 9.1-fp2 (including) 9.1-fp2 (including)
Db2 Ibm 9.1-fp3 (including) 9.1-fp3 (including)
Db2 Ibm 9.1-fp3a (including) 9.1-fp3a (including)
Db2 Ibm 9.1-fp4 (including) 9.1-fp4 (including)
Db2 Ibm 9.1-fp4a (including) 9.1-fp4a (including)
Db2 Ibm 9.5-fp1 (including) 9.5-fp1 (including)

References