
CVE-2014-0907 – IBM DB2 Privilege Escalation
https://notcve.org/view.php?id=CVE-2014-0907
30 May 2014 — Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library. Múltiples vulnerabilidades de búsqueda de ruta no confiable en programas no especificados (1) setuid y (2) setgid en IBM DB2 9.5, 9.7 anterior a FP9a, 9.8, 10.1 anterior a FP3a y 10.5 anterior a FP3a en Linux y UNIX permiten a usuarios locales ganar ... • http://packetstormsecurity.com/files/126940/IBM-DB2-Privilege-Escalation.html •

CVE-2013-6744
https://notcve.org/view.php?id=CVE-2013-6744
30 May 2014 — The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority. La infraestructura Stored Procedure en IBM DB2 9.5, 9.7 anterior a FP9a, 10.1 anterior a FP3a y 10.5 anterior a FP3a en Windows permite a usuarios remotos autenticados ganar privilegios mediante el aprovechamiento del privilegio CONNECT y la autoridad CREATE_EX... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC98849 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-6717
https://notcve.org/view.php?id=CVE-2013-6717
19 Dec 2013 — The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP2, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service (database outage and deactivation) via unspecified vectors. El motor de consultas OLAP en IBM DB2 y DB2 Connect 9.7 hasta FP9, 9.8 hasta FP3, y 10.6 hasta FP2, y la pureScale Feature 9.8 para Enterprise Server Edition, permite ausuarios autenticados remotamente... • http://secunia.com/advisories/56451 •

CVE-2013-5466
https://notcve.org/view.php?id=CVE-2013-5466
18 Dec 2013 — The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors. La librería XSLT en IBM DB2 y DB2 Connect 9.5 hasta 10.5, y DB2 pureScale Feature 9.8 para Enterprise Server Edition, permite a usuarios remotos autenticados causar una denegación de servicio a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC97402 •

CVE-2013-4033
https://notcve.org/view.php?id=CVE-2013-4033
28 Aug 2013 — IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority. IBM DB2 y DB2 Connect v9.7 hasta FP8, v9.8 hasta FP5, v10.1 hasta FP2, y v10.5 hasta FP1 permiten a los usuarios remotos autenticados ejecutar instrucciones DML mediante el aprovechamiento de la autoridad "EXPLAIN". • http://www-01.ibm.com/support/docview.wss?uid=swg1IC94523 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-3475
https://notcve.org/view.php?id=CVE-2013-3475
05 Jun 2013 — Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors. Desbordamiento de búfer basado en pila en db2aud en Audit Facility de IBM DB2 y DB2 Connect v9.1, v9.5, v9.7, v9.8 y v10.1, como se utiliza en Smart System Analytics 7600 y otros productos, permite a usuarios locales conseguir privilegios a través de vectores no especifica... • http://secunia.com/advisories/52663 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-4826
https://notcve.org/view.php?id=CVE-2012-4826
20 Oct 2012 — Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure. Desbordamiento de búfer basado en pila en la infraestructura SQL/PSM (alias SQL Persistent Stored Module) Stored Procedure (SP) en IBM DB2 v9.1, v9.5, v9.7 antes de FP7, v9.8, y v10.1, podría permitir a usuarios remotos autenticados ejecutar código... • http://osvdb.org/86414 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-0713
https://notcve.org/view.php?id=CVE-2012-0713
24 Aug 2012 — Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors. Vulnerabilidad no especificada en la característica XML en IBM DB2 v9.7 anterior a FP6 en Linux, UNIX y Windows permite a usuarios remotos autenticados leer archivos XML arbitrarios a través de vectores desconocidos. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC81462 •

CVE-2012-2196
https://notcve.org/view.php?id=CVE-2012-2196
25 Jul 2012 — IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP_CFG_C2 stored procedure. IBM DB2 v9.1 antes de FP12, v9.5 hasta el FP9, v9.7 hasta el FP6, v9.8 hasta el FP5 y v10.1 permite a atacantes remotos leer archivos XML de su elección a través de los procedimientos almacenados (1) GET_WRAP_CFG_C o (2) GET_WRAP_CFG_C2. • http://secunia.com/advisories/49919 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2012-2197
https://notcve.org/view.php?id=CVE-2012-2197
25 Jul 2012 — Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges. Un desbordamiento de búfer basado en pila en la infraestructura de procedimiento almacenado de Java ('Java Stored Procedure infrastructure') en IBM DB2 v9.1 antes de FP12, v9.5 a FP9, v9.7 a FP6, v9.8 a FP5, y v10.1 permite a usuarios rem... • http://secunia.com/advisories/49919 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •