CVE Vulnerabilities

CVE-2012-0712

Published: Mar 20, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.

Affected Software

NameVendorStart VersionEnd Version
Db2Ibm9.5 (including)9.5 (including)
Db2Ibm9.5-fp1 (including)9.5-fp1 (including)
Db2Ibm9.5-fp2 (including)9.5-fp2 (including)
Db2Ibm9.5-fp2a (including)9.5-fp2a (including)
Db2Ibm9.5-fp3 (including)9.5-fp3 (including)
Db2Ibm9.5-fp3a (including)9.5-fp3a (including)
Db2Ibm9.5-fp3b (including)9.5-fp3b (including)
Db2Ibm9.5-fp4 (including)9.5-fp4 (including)
Db2Ibm9.5-fp4a (including)9.5-fp4a (including)
Db2Ibm9.5-fp5 (including)9.5-fp5 (including)
Db2Ibm9.5-fp6 (including)9.5-fp6 (including)
Db2Ibm9.5-fp6a (including)9.5-fp6a (including)
Db2Ibm9.5-fp7 (including)9.5-fp7 (including)
Db2Ibm9.5-fp8 (including)9.5-fp8 (including)
Db2Ibm9.7 (including)9.7 (including)
Db2Ibm9.7-fp1 (including)9.7-fp1 (including)
Db2Ibm9.7-fp2 (including)9.7-fp2 (including)
Db2Ibm9.7-fp3 (including)9.7-fp3 (including)
Db2Ibm9.7-fp3a (including)9.7-fp3a (including)
Db2Ibm9.7-fp4 (including)9.7-fp4 (including)
Db2Ibm9.7-fp5 (including)9.7-fp5 (including)
Db2Ibm9.8 (including)9.8 (including)
Db2Ibm9.8-fp3 (including)9.8-fp3 (including)
Db2Ibm9.8-fp4 (including)9.8-fp4 (including)
Db2excUbuntuhardy*
Db2excUbuntulucid*
Db2excUbuntuprecise*
Db2excUbuntuupstream*

References