Boletines de Vulnerabilidades

IBM Security Bulletin: IBM® DB2® LUW contains a denial of service vulnerability using a SELECT statement with a subquery containing a UNION (CVE-2014-3095)


Información sobre el sistema

   
Software afectado IBM

Descripción

IBM DB2 SQL engine contains a denial of service vulnerability where a malicious user could exploit and cause a disruption of service. CVE(s): CVE-2014-3095 Affected product(s) and affected version(s): All fix pack levels for IBM DB2 V9.5, V9.7, V10.1 and V10.5 editions listed below and running on AIX, Linux, HP, Solaris or Windows are affected : IBM® DB2® Express Edition IBM® DB2® Workgroup Server Edition IBM® DB2® Enterprise Server Edition IBM® DB2®

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_db2_luw_contains_a_denial_of_service_vulnerability_using_a_select_statement_with_a_subquery_containing_a_union_cve_2014_3095?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-3095 ,CVE-2014-3094 ,CVE-2013-6371 and CVE-2014-0411.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-09-04

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT