
CVE-2013-4032
https://notcve.org/view.php?id=CVE-2013-4032
02 Oct 2013 — The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a multi-node configuration is used, allows remote attackers to cause a denial of service via vectors involving arbitrary data. Fast Communications Manager (FCM) en IBM DB2 Enterprise Server Edition y Advanced Enterprise Server Edition 10.1 anterior a la versión FP3 y 10.5, cuando se utiliza una configuración de varios nodos, permite a atacantes remotos causar una d... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC94434 • CWE-20: Improper Input Validation •

CVE-2013-4025
https://notcve.org/view.php?id=CVE-2013-4025
25 Sep 2013 — IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. IBM Data Studio Web Console 3.x anterior a la versión 3.2, Optim Performance Manager 5.x anterior a la versión 5.2, InfoSphere Optim Configuration Manager 2.x anterior a ... • http://www-01.ibm.com/support/docview.wss?uid=swg21650504 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-4024
https://notcve.org/view.php?id=CVE-2013-4024
25 Sep 2013 — IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network. IBM Data Studio Web Console 3.x anterior a la versión 3,2, Optim Performance Manager 5.x anterior a la versión 5.2, InfoSphere Optim Configuration Manager 2.x anterior a la versión 2.2, y DB2 Recovery Expert 2.x soporta HTTP... • http://www-01.ibm.com/support/docview.wss?uid=swg21650504 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-4022
https://notcve.org/view.php?id=CVE-2013-4022
25 Sep 2013 — IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown vectors. IBM Data Studio Web Console v3.x anterior a v3.2, Optim Performance Manager v5.x anterior a v5.2, InfoSphere Optim Configuration Manager v2.x anterior a v2.2 y DB2 Recovery Expert v2.x ... • http://www-01.ibm.com/support/docview.wss?uid=swg21650504 • CWE-255: Credentials Management Errors •

CVE-2013-4033
https://notcve.org/view.php?id=CVE-2013-4033
28 Aug 2013 — IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority. IBM DB2 y DB2 Connect v9.7 hasta FP8, v9.8 hasta FP5, v10.1 hasta FP2, y v10.5 hasta FP1 permiten a los usuarios remotos autenticados ejecutar instrucciones DML mediante el aprovechamiento de la autoridad "EXPLAIN". • http://www-01.ibm.com/support/docview.wss?uid=swg1IC94523 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-3475
https://notcve.org/view.php?id=CVE-2013-3475
05 Jun 2013 — Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors. Desbordamiento de búfer basado en pila en db2aud en Audit Facility de IBM DB2 y DB2 Connect v9.1, v9.5, v9.7, v9.8 y v10.1, como se utiliza en Smart System Analytics 7600 y otros productos, permite a usuarios locales conseguir privilegios a través de vectores no especifica... • http://secunia.com/advisories/52663 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-4826
https://notcve.org/view.php?id=CVE-2012-4826
20 Oct 2012 — Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure. Desbordamiento de búfer basado en pila en la infraestructura SQL/PSM (alias SQL Persistent Stored Module) Stored Procedure (SP) en IBM DB2 v9.1, v9.5, v9.7 antes de FP7, v9.8, y v10.1, podría permitir a usuarios remotos autenticados ejecutar código... • http://osvdb.org/86414 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-3324
https://notcve.org/view.php?id=CVE-2012-3324
25 Sep 2012 — Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field. Vulnerabilidad de salto de directorio en el módulo UTL_FILE en IBM DB2 y DB2 Connect v10.1 antes de FP1 en Windows permite a usuarios remotos autenticados modificar, eliminar o leer archivos de su elección a través de una ruta en el campo Archivo ('file'). • http://www-01.ibm.com/support/docview.wss?uid=swg1IC85513 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2012-0713
https://notcve.org/view.php?id=CVE-2012-0713
24 Aug 2012 — Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors. Vulnerabilidad no especificada en la característica XML en IBM DB2 v9.7 anterior a FP6 en Linux, UNIX y Windows permite a usuarios remotos autenticados leer archivos XML arbitrarios a través de vectores desconocidos. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC81462 •

CVE-2012-2196
https://notcve.org/view.php?id=CVE-2012-2196
25 Jul 2012 — IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP_CFG_C2 stored procedure. IBM DB2 v9.1 antes de FP12, v9.5 hasta el FP9, v9.7 hasta el FP6, v9.8 hasta el FP5 y v10.1 permite a atacantes remotos leer archivos XML de su elección a través de los procedimientos almacenados (1) GET_WRAP_CFG_C o (2) GET_WRAP_CFG_C2. • http://secunia.com/advisories/49919 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •