CVE-2008-0698Improper Restriction of Operations within the Bounds of a Memory Buffer in IBM DB2

Severity
10.0CRITICALNVD
NVD7.8CNA7.8
EPSS
0.6%
top 29.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateMay 3

Description

Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

NVDibm/db28.0+2

🔴Vulnerability Details

4
GHSA
GHSA-52f6-v5q4-q9mc: Buffer overflow in the DAS server in IBM DB2 UDB before 82022-05-03
GHSA
GHSA-xrxm-c9j3-54pp: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of2022-05-01
CVEList
CVE-2007-3676: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of2008-02-12
CVEList
CVE-2008-0698: Buffer overflow in the DAS server in IBM DB2 UDB before 82008-02-12
CVE-2008-0698 — IBM DB2 vulnerability | cvebase