CVE-2009-4327Improper Input Validation in IBM DB2

Severity
5.0MEDIUMNVD
EPSS
1.0%
top 22.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 3

Description

The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows attackers to cause a denial of service (memory consumption) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDibm/db29.5, 9.7+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-prvm-2m7g-3vrf: The Common Code Infrastructure component in IBM DB2 92022-05-03
CVEList
CVE-2009-4327: The Common Code Infrastructure component in IBM DB2 92009-12-16
CVE-2009-4327 — Improper Input Validation in IBM DB2 | cvebase