Denial of Service vulnerability in IBM DB2 software
CVE-2008-3858

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 August 2008

What is CVE-2008-3858?

The Downlevel DB2RA Support component in IBM DB2 version 9.1 prior to Fixpak 4a is susceptible to a denial of service attack. By sending a specially crafted CONNECT data stream that mimics a V7 client connect request, attackers can trigger an instance crash, disrupting services and potentially affecting the availability of the database system. Organizations using this version should ensure that they are updated to the latest patches to mitigate this vulnerability and enhance their security posture.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.