VulnerabilityModified
CVE-2012-0712
The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
MEDIUM 4.0EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- ibm/db2
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC81379
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC81380
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC81837
- http://www-01.ibm.com/support/docview.wss?uid=swg21588098Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73496
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14450
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC81379
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC81380
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC81837
- http://www-01.ibm.com/support/docview.wss?uid=swg21588098Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73496
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14450
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.