Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilty in XMLC affects IBM® DB2® LUW (CVE-2016-0729, CVE-2016-4463)

   
Affected software IBM
 
IBM DB2 for LUW bundles a XMLC library that is affected by CVE-2016-0729. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially crafted statement. This may cause the DB2 server to terminate abnormally or execute arbitary code.CVE(s): CVE-2016-0729, CVE-2016-4463Affected product(s) and affected version(s):All fix pack levels of IBM DB2 V9.7, V10.1, V10.5 and V11.1 editions listed below and running on AIX, Linux, HP, Solaris or Windows are affected IBM®

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-vulnerabilty-in-xmlc-affects-ibm-db2-luw-cve-2016-0729-cve-2016-4463/