
CVE-2012-2197
https://notcve.org/view.php?id=CVE-2012-2197
25 Jul 2012 — Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges. Un desbordamiento de búfer basado en pila en la infraestructura de procedimiento almacenado de Java ('Java Stored Procedure infrastructure') en IBM DB2 v9.1 antes de FP12, v9.5 a FP9, v9.7 a FP6, v9.8 a FP5, y v10.1 permite a usuarios rem... • http://secunia.com/advisories/49919 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-2194
https://notcve.org/view.php?id=CVE-2012-2194
25 Jul 2012 — Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors. Una vulnerabilidad de salto de directorio en el procedimiento almacenado SQLJ.DB2_INSTALL_JAR en IBM DB2 v9.1 antes de FP12, v9.5 hasta FP9, v9.7 hasta FP6, v9.8 hasta FP5 y v10.1 permite a atacantes remotos reemplazar los archivos JAR a través de vectores no especificados. • http://secunia.com/advisories/49919 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2012-2180
https://notcve.org/view.php?id=CVE-2012-2180
20 Jun 2012 — The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5 allows remote attackers to cause a denial of service (NULL pointer dereference, and resource consumption or daemon crash) via a crafted request. La funcionalidad de encadenamiento en el módulo de arquitectura de bases de datos relacionales distribuidas - 'Distributed Relational Database Architecture'(DRDA) en IBM DB2 v9.7 antes de FP6 y 9.8 antes de FP5, permite a atacant... • http://www.ibm.com/support/docview.wss?uid=swg1IC82234 •

CVE-2012-1796
https://notcve.org/view.php?id=CVE-2012-1796
20 Mar 2012 — Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors. Vulnerabilidad no especificada en IBM Tivoli Monitoring Agent (ITMA), tal como se utiliza en IBM DB2 9.5 antes de FP9 en UNIX, permite a usuarios locales conseguir privilegios a través de vectores desconocidos. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC79970 •

CVE-2012-0710
https://notcve.org/view.php?id=CVE-2012-0710
20 Mar 2012 — IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request. IBM DB2 9.1 antes de FP11, 9.5 antes de FP9, 9.7 antes de FP5, y 9.8 antes de FP4 permite a atacantes remotos causar una denegación de servicio (caída de demonio) a través de una solicitud Distributed Relational Database Architecture (DRDA) modificada. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC76781 • CWE-20: Improper Input Validation •

CVE-2012-1797
https://notcve.org/view.php?id=CVE-2012-1797
20 Mar 2012 — IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors. IBM DB2 v9.5 utiliza permisos de escritura globales para nodes.reg, lo que tiene un impacto y vectores de ataque no especificados. • http://www-01.ibm.com/support/docview.wss?crawler=1&uid=swg1IC79518 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-0711
https://notcve.org/view.php?id=CVE-2012-0711
20 Mar 2012 — Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow. Un error de entero sin signo en el proceso db2dasrrm del servidor de administración de DB2 (DAS) en IBM DB2 v9.1 hasta FP11, v9.5 antes de vFP9, y v9.7 hasta FP5 para UNIX permite a atacantes remotos ejecutar código de su el... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC80561 • CWE-189: Numeric Errors •

CVE-2012-0709
https://notcve.org/view.php?id=CVE-2012-0709
20 Mar 2012 — IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements. IBM DB2 v9.5 anteriores a vFP9, v9.7 hasta vFP5, y v9.8 hasta vFP4 no comprueban las variables de forma adecuada, lo que permite a usuarios remotos autenticados evitar las restricciones de visionado de datos de tablas, mediante la ele... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC81387 • CWE-20: Improper Input Validation •

CVE-2012-0712
https://notcve.org/view.php?id=CVE-2012-0712
20 Mar 2012 — The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression. La función de XML en IBM DB2 v9.5 antes de FP9, v9.7 hasta FP5, y v9.8 hasta FP4 permite a usuarios remotos autenticados provocar una denegación de servicio (bucle infinito) llamando a la función XMLPARSE con una expresión de cadena modificada. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC81379 • CWE-399: Resource Management Errors •

CVE-2011-4435
https://notcve.org/view.php?id=CVE-2011-4435
11 Nov 2011 — The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers to obtain sensitive information via HTTP requests. El componente de servidor web en Consolidation and Analysis Engine (CAE) Server en DB2 Query Monitor en IBM DB2 Tools v2.3.0 para z/OS no impide la exploración de directorios, lo que permite a atacantes remotos obtener información sensible a través de peticiones... • http://secunia.com/advisories/46487 • CWE-264: Permissions, Privileges, and Access Controls •