Multiple IBM DB2 product file leakage vulnerabilities (CVE-2015-8910)
Multiple IBM DB2 product file leakage vulnerabilities (CVE-2015-8910)
Release date:
Updated on:
Affected Systems:
IBM DB2 9.8-FP5
IBM DB2 9.7-FP10
IBM DB2 10.5-FP5
IBM DB2 10.1-FP5
Description:
Bugtraq id: 75949
CVE (CAN) ID: CVE-2014-8910
IBM DB2 is a large commercial relational database system.
On Linux, UNIX, and Windows platforms, IBM DB2 9.7-FP10, 9.8-FP5, 10.1-FP5, and 10.5-FP5 have the file leakage vulnerability, authenticated remote users can exploit this vulnerability to read arbitrary text files by using XML/XSLT functions constructed in SELECT statements.
<* Source: vendor
*>
Suggestion:
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/support/docview.wss? Uid = swg21697988
Http://www-01.ibm.com/support/docview.wss? Uid = swg1IT06354
Http://www-01.ibm.com/support/docview.wss? Uid = swg1IT06355
Http://www-01.ibm.com/support/docview.wss? Uid = swg1IT06356
Http://www-01.ibm.com/support/docview.wss? Uid = swg1IT06353
This article permanently updates the link address: