CVE-2008-3858
published 2008-08-28CVE-2008-3858: The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.85%
76.7th percentile
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | <= 8.0 | — |
| ibm | db2 | — | — |
| ibm | db2_universal_database | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r9rm-x6jp-8r54: IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that sim
ghsa_unreviewed·2022-05-03·CVSS 4.3
CVE-2008-3958 [MEDIUM] GHSA-r9rm-x6jp-8r54: IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that sim
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
GHSA
GHSA-452f-6cjx-8x7j: The Downlevel DB2RA Support component in IBM DB2 9
ghsa_unreviewed·2022-05-02
CVE-2008-3858 [MEDIUM] GHSA-452f-6cjx-8x7j: The Downlevel DB2RA Support component in IBM DB2 9
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/48428http://www-1.ibm.com/support/docview.wss?uid=swg1IZ07299http://www-1.ibm.com/support/docview.wss?uid=swg21255607http://www.securityfocus.com/bid/29601https://exchange.xforce.ibmcloud.com/vulnerabilities/45138http://osvdb.org/48428http://www-1.ibm.com/support/docview.wss?uid=swg1IZ07299http://www-1.ibm.com/support/docview.wss?uid=swg21255607http://www.securityfocus.com/bid/29601https://exchange.xforce.ibmcloud.com/vulnerabilities/45138
2008-08-28
Published