CVE-2019-4014

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.

Published : 2019-04-03 14:29 Updated : 2019-10-09 23:50

CVSS

There is no CVSS for this CVE.
Vendor Product Version URI
Ibm Db2 9.7.0.0 cpe:/a:ibm:db2:9.7.0.0
Ibm Db2 9.7.0.1 cpe:/a:ibm:db2:9.7.0.1
Ibm Db2 9.7.0.2 cpe:/a:ibm:db2:9.7.0.2
Ibm Db2 9.7.0.3 cpe:/a:ibm:db2:9.7.0.3
Ibm Db2 9.7.0.4 cpe:/a:ibm:db2:9.7.0.4
Ibm Db2 9.7.0.5 cpe:/a:ibm:db2:9.7.0.5
Ibm Db2 9.7.0.6 cpe:/a:ibm:db2:9.7.0.6
Ibm Db2 9.7.0.7 cpe:/a:ibm:db2:9.7.0.7
Ibm Db2 9.7.0.8 cpe:/a:ibm:db2:9.7.0.8
Ibm Db2 9.7.0.9 cpe:/a:ibm:db2:9.7.0.9
Ibm Db2 9.7.0.10 cpe:/a:ibm:db2:9.7.0.10
Ibm Db2 9.7.0.11 cpe:/a:ibm:db2:9.7.0.11
Ibm Db2 10.1.0.0 cpe:/a:ibm:db2:10.1.0.0
Ibm Db2 10.1.0.1 cpe:/a:ibm:db2:10.1.0.1
Ibm Db2 10.1.0.2 cpe:/a:ibm:db2:10.1.0.2
Ibm Db2 10.1.0.3 cpe:/a:ibm:db2:10.1.0.3
Ibm Db2 10.1.0.4 cpe:/a:ibm:db2:10.1.0.4
Ibm Db2 10.1.0.5 cpe:/a:ibm:db2:10.1.0.5
Ibm Db2 10.1.0.6 cpe:/a:ibm:db2:10.1.0.6
Ibm Db2 10.5.0.0 cpe:/a:ibm:db2:10.5.0.0
Ibm Db2 10.5.0.1 cpe:/a:ibm:db2:10.5.0.1
Ibm Db2 10.5.0.2 cpe:/a:ibm:db2:10.5.0.2
Ibm Db2 10.5.0.3 cpe:/a:ibm:db2:10.5.0.3
Ibm Db2 10.5.0.4 cpe:/a:ibm:db2:10.5.0.4
Ibm Db2 10.5.0.5 cpe:/a:ibm:db2:10.5.0.5
Ibm Db2 10.5.0.6 cpe:/a:ibm:db2:10.5.0.6
Ibm Db2 10.5.0.7 cpe:/a:ibm:db2:10.5.0.7
Ibm Db2 10.5.0.8 cpe:/a:ibm:db2:10.5.0.8
Ibm Db2 10.5.0.9 cpe:/a:ibm:db2:10.5.0.9
Ibm Db2 10.5.0.10 cpe:/a:ibm:db2:10.5.0.10
Ibm Db2 11.1.0.0 cpe:/a:ibm:db2:11.1.0.0
Ibm Db2 11.1.1.1 cpe:/a:ibm:db2:11.1.1.1
Ibm Db2 11.1.2.2 cpe:/a:ibm:db2:11.1.2.2
Ibm Db2 11.1.3.3 cpe:/a:ibm:db2:11.1.3.3
Ibm Db2 11.1.4.4 cpe:/a:ibm:db2:11.1.4.4
  1. Ibm (1) Search CVE
    1. Db2 (35) Search CVE
      1. 9.7.0.0
      2. 9.7.0.1
      3. 9.7.0.2
      4. 9.7.0.3
      5. 9.7.0.4
      6. 9.7.0.5
      7. 9.7.0.6
      8. 9.7.0.7
      9. 9.7.0.8
      10. 9.7.0.9
      11. 9.7.0.10
      12. 9.7.0.11
      13. 10.1.0.0
      14. 10.1.0.1
      15. 10.1.0.2
      16. 10.1.0.3
      17. 10.1.0.4
      18. 10.1.0.5
      19. 10.1.0.6
      20. 10.5.0.0
      21. 10.5.0.1
      22. 10.5.0.2
      23. 10.5.0.3
      24. 10.5.0.4
      25. 10.5.0.5
      26. 10.5.0.6
      27. 10.5.0.7
      28. 10.5.0.8
      29. 10.5.0.9
      30. 10.5.0.10
      31. 11.1.0.0
      32. 11.1.1.1
      33. 11.1.2.2
      34. 11.1.3.3
      35. 11.1.4.4

CWE

ID Name Description Links
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer. CVE

History of changes

Date Event
2019-10-09 23:50

New CVE