Buffer Overflow Vulnerability in IBM DB2 Product
CVE-2008-3854

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
28 August 2008

Summary

Multiple stack-based buffer overflows in IBM DB2 versions 9.1 prior to Fixpak 5 and version 9.5 prior to Fixpak 1 enable remote attackers to exploit vulnerabilities through XQuery statements and associated functions. This can lead to service disruptions, impacting database availability and integrity. Specifically, vulnerabilities arise in the handling of XMLQUERY, XMLEXISTS, XMLTABLE statements, and the sqlrlaka function, allowing for potential system outages.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.