CVE-2008-0699
Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 5.20% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- ibm/db2
- Source
- cve@mitre.org
References
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXTVendor Advisory
- http://osvdb.org/41795Broken Link
- http://secunia.com/advisories/28771Third Party Advisory
- http://secunia.com/advisories/29022Third Party Advisory
- http://secunia.com/advisories/29784Third Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06972Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06973Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10917Patch, Vendor Advisory
- http://www.appsecinc.com/resources/alerts/db2/2008-02.shtmlThird Party Advisory
- http://www.securityfocus.com/archive/1/491075/100/0/threadedThird Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0401Third Party Advisory
- ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXTVendor Advisory
- http://osvdb.org/41795Broken Link
- http://secunia.com/advisories/28771Third Party Advisory
- http://secunia.com/advisories/29022Third Party Advisory
- http://secunia.com/advisories/29784Third Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06972Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06973Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10917Patch, Vendor Advisory
- http://www.appsecinc.com/resources/alerts/db2/2008-02.shtmlThird Party Advisory
- http://www.securityfocus.com/archive/1/491075/100/0/threadedThird Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0401Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.