Remote Denial of Service Vulnerability (CVE-2014-8901) for multiple IBM DB2 Products)
Release date:
Updated on:
Affected Systems:
IBM DB2 <10.5 FP5
IBM DB2 9.8-FP5
IBM DB2 9.7-FP10
IBM DB2 9.5-FP10
IBM DB2 10.1-FP4
Description:
Bugtraq id: 71734
CVE (CAN) ID: CVE-2014-8901
IBM DB2 is a large commercial relational database system.
In versions earlier than IBM DB2 9.5-FP10, 9.7-FP10, 9.8-FP5, 10.1-FP4, and 10.5 FP5, a remote denial of service vulnerability exists in implementation. authenticated remote users can query the constructed XML data, this vulnerability can exhaust cpu resources and cause denial of service.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: http://xforce.iss.net/xforce/xfdb/99110
*>
Suggestion:
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/support/docview.wss? Uid = swg21692358
This article permanently updates the link address: