Stack-based buffer overflow vulnerability in the Java Stored Procedure infrastructure in IBM DB2 (Linux)ID: oval:org.secpod.oval:def:6524 | Date: (C)2012-08-07 (M)2021-09-12 |
Class: VULNERABILITY | Family: unix |
The host is installed with IBM DB2 9.1 before FP12 or 9.5 through FP9 or 9.7 through FP6 or 9.8 through FP5 or 10.1 and is prone to stack-based buffer overflow vulnerability. A flaw is present in the application, which fails to handle Java Stored Procedure infrastructure. Successful exploitation allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.