Total vulnerabilities in the database
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.
Software | From | Fixed in |
---|---|---|
ibm / db2_universal_database | 7.1 | 7.1.x |
ibm / db2_universal_database | 8.1 | 8.1.x |
ibm / db2_universal_database | 8.0 | 8.0.x |
ibm / db2_universal_database | 7.0 | 7.0.x |
ibm / db2_universal_database | 7.2 | 7.2.x |